Hi Tony,

I've not posted on this topic before. Anyways, good to know that it is 
being addressed. Any tentative date for this fix?

Thanks,
Vijay

On Wednesday, August 3, 2016 at 8:23:31 PM UTC+5:30, tony tam wrote:
>
> Hi Vijay, I believe you already reached out on this.  Expect it will be 
> addressed shortly.
>
> On Aug 3, 2016, at 3:36 PM, Vijay <[email protected] <javascript:>> 
> wrote:
>
> Hi,
>
> Our security team has found vulnerabilities in handlebars.js version 2.0.0 
> which is being used by Swagger UI.
> References provided:
>
> https://yahoo-security.tumblr.com/post/128130790295/paranoid-labs-open-source-and-solving-xss-in
> https://github.com/wycats/handlebars.js/pull/1083 
> https://blog.srcclr.com/handlebars_vulnerability_research_findings/
>
> Is it already a known issue and being taken care to upgrade to 
> handlebars.js latest stable version ?
>
> Thanks,
> Vijay
>
>
> -- 
> You received this message because you are subscribed to the Google Groups 
> "Swagger" group.
> To unsubscribe from this group and stop receiving emails from it, send an 
> email to [email protected] <javascript:>.
> For more options, visit https://groups.google.com/d/optout.
>
>
>

-- 
You received this message because you are subscribed to the Google Groups 
"Swagger" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to