We’ve pushed the updated version to master yesterday, please check it out.

 

 

 

From: <[email protected]> on behalf of Vijay 
<[email protected]>
Reply-To: "[email protected]" 
<[email protected]>
Date: Wednesday, 3 August 2016 at 23:00
To: Swagger <[email protected]>
Subject: Re: Vulnerability in handlebars.js version 2.0.0

 

Hi Tony, 

 

I've not posted on this topic before. Anyways, good to know that it is being 
addressed. Any tentative date for this fix?

 

Thanks,

Vijay

On Wednesday, August 3, 2016 at 8:23:31 PM UTC+5:30, tony tam wrote: 

Hi Vijay, I believe you already reached out on this.  Expect it will be 
addressed shortly. 

 

On Aug 3, 2016, at 3:36 PM, Vijay <[email protected]> wrote:

 

Hi, 

 

Our security team has found vulnerabilities in handlebars.js version 2.0.0 
which is being used by Swagger UI.

References provided:

https://yahoo-security.tumblr.com/post/128130790295/paranoid-labs-open-source-and-solving-xss-in
https://github.com/wycats/handlebars.js/pull/1083 
https://blog.srcclr.com/handlebars_vulnerability_research_findings/

 

Is it already a known issue and being taken care to upgrade to handlebars.js 
latest stable version ?

 

Thanks,

Vijay

 

 

-- 
You received this message because you are subscribed to the Google Groups 
"Swagger" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

 

-- 
You received this message because you are subscribed to the Google Groups 
"Swagger" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

-- 
You received this message because you are subscribed to the Google Groups 
"Swagger" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to