Hi Vijay, I believe you already reached out on this.  Expect it will be 
addressed shortly.

> On Aug 3, 2016, at 3:36 PM, Vijay <[email protected]> wrote:
> 
> Hi,
> 
> Our security team has found vulnerabilities in handlebars.js version 2.0.0 
> which is being used by Swagger UI.
> References provided:
> https://yahoo-security.tumblr.com/post/128130790295/paranoid-labs-open-source-and-solving-xss-in
>  
> <https://yahoo-security.tumblr.com/post/128130790295/paranoid-labs-open-source-and-solving-xss-in>
> https://github.com/wycats/handlebars.js/pull/1083 
> <https://github.com/wycats/handlebars.js/pull/1083> 
> https://blog.srcclr.com/handlebars_vulnerability_research_findings/ 
> <https://blog.srcclr.com/handlebars_vulnerability_research_findings/>
> 
> Is it already a known issue and being taken care to upgrade to handlebars.js 
> latest stable version ?
> 
> Thanks,
> Vijay
> 
> 
> -- 
> You received this message because you are subscribed to the Google Groups 
> "Swagger" group.
> To unsubscribe from this group and stop receiving emails from it, send an 
> email to [email protected] 
> <mailto:[email protected]>.
> For more options, visit https://groups.google.com/d/optout 
> <https://groups.google.com/d/optout>.

-- 
You received this message because you are subscribed to the Google Groups 
"Swagger" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to