Vulnerability in handlebars.js version 2.0.0

117 views
Skip to first unread message

Vijay

unread,
Aug 3, 2016, 9:36:53 AM8/3/16
to Swagger
Hi,

Our security team has found vulnerabilities in handlebars.js version 2.0.0 which is being used by Swagger UI.
References provided:

Is it already a known issue and being taken care to upgrade to handlebars.js latest stable version ?

Thanks,
Vijay

tony tam

unread,
Aug 3, 2016, 10:53:31 AM8/3/16
to swagger-sw...@googlegroups.com
Hi Vijay, I believe you already reached out on this.  Expect it will be addressed shortly.

--
You received this message because you are subscribed to the Google Groups "Swagger" group.
To unsubscribe from this group and stop receiving emails from it, send an email to swagger-swaggers...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Vijay

unread,
Aug 4, 2016, 2:00:09 AM8/4/16
to Swagger
Hi Tony,

I've not posted on this topic before. Anyways, good to know that it is being addressed. Any tentative date for this fix?

Thanks,
Vijay
To unsubscribe from this group and stop receiving emails from it, send an email to swagger-swaggersocket+unsub...@googlegroups.com.

Ron Ratovsky

unread,
Aug 4, 2016, 11:27:25 AM8/4/16
to swagger-sw...@googlegroups.com

We’ve pushed the updated version to master yesterday, please check it out.

To unsubscribe from this group and stop receiving emails from it, send an email to swagger-swaggers...@googlegroups.com.


For more options, visit https://groups.google.com/d/optout.

 

--

You received this message because you are subscribed to the Google Groups "Swagger" group.

To unsubscribe from this group and stop receiving emails from it, send an email to swagger-swaggers...@googlegroups.com.

Ron Ratovsky

unread,
Aug 4, 2016, 11:30:42 AM8/4/16
to swagger-sw...@googlegroups.com

My bad, looks like we missed something, but we’re definitely working on it, will keep you posted.

tony tam

unread,
Aug 24, 2016, 2:40:54 PM8/24/16
to Swagger
Hi, FYI swagger-ui 2.2.2 has been released and address XSS issues, handlebars, and a whole host of other items.  Please see here for release notes:


To unsubscribe from this group and stop receiving emails from it, send an email to swagger-swaggersocket+unsub...@googlegroups.com.


For more options, visit https://groups.google.com/d/optout.

--
You received this message because you are subscribed to the Google Groups "Swagger" group.

To unsubscribe from this group and stop receiving emails from it, send an email to swagger-swaggersocket+unsub...@googlegroups.com.


For more options, visit https://groups.google.com/d/optout.

--
You received this message because you are subscribed to the Google Groups "Swagger" group.

To unsubscribe from this group and stop receiving emails from it, send an email to swagger-swaggersocket+unsub...@googlegroups.com.

Vijaya Sekhar Reddy P

unread,
Aug 25, 2016, 5:27:50 AM8/25/16
to swagger-sw...@googlegroups.com
Thanks a lot for the update!

Thanks,
Vijay

To unsubscribe from this group and stop receiving emails from it, send an email to swagger-swaggersocket+unsubscri...@googlegroups.com.


For more options, visit https://groups.google.com/d/optout.

--
You received this message because you are subscribed to the Google Groups "Swagger" group.

To unsubscribe from this group and stop receiving emails from it, send an email to swagger-swaggersocket+unsubscri...@googlegroups.com.


For more options, visit https://groups.google.com/d/optout.

--
You received this message because you are subscribed to the Google Groups "Swagger" group.

To unsubscribe from this group and stop receiving emails from it, send an email to swagger-swaggersocket+unsubscri...@googlegroups.com.


For more options, visit https://groups.google.com/d/optout.

--
You received this message because you are subscribed to a topic in the Google Groups "Swagger" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/swagger-swaggersocket/T-WVBjvpTw0/unsubscribe.
To unsubscribe from this group and all its topics, send an email to swagger-swaggersocket+unsub...@googlegroups.com.
Reply all
Reply to author
Forward
0 new messages