Re: jQuery 1.8 vulnerability

2018-05-10 Thread David Trowbridge
Daniel, Review board does not use either strInput or cross-domain ajax requests, so it is not affected by either of these vulnerabilities. -David On Thu, May 10, 2018 at 9:19 AM Daniel wrote: > Hello, > > My corp security department prevents me using the ReviewBoard

jQuery 1.8 vulnerability

2018-05-10 Thread Daniel
Hello, My corp security department prevents me using the ReviewBoard because there are publicly known vulnerabilities in the one of RB's components (particularly jQuery 1.8). Would it possible for the community to mitigate those issues ? CVE-2015-9251