Jenkins YUI2 Security Vulnerabilities

103 views
Skip to first unread message

Mike Bragg

unread,
Jul 23, 2018, 5:58:52 PM7/23/18
to yui-support
An external team just came in and scanned our environment.  One of the things they found was the YUI scripts we old and had vulnerabilities.  I downloaded the latest Jenkins war file and it had the same 2.9.0 versions with the vulnerability.  Below is an example:

/static/12057b98/scripts/yui/event/event-min.js

 

https://www.cvedetails.com/cve/CVE-2013-4940/

 

Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility component in Yahoo! YUI 3.10.2, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted string in a URL. NOTE: this vulnerability exists because of a CVE-2013-4939 regression.
Publish Date : 2013-07-29 Last Update Date : 2013-10-03

 

I have not been able to find anything that says how to update these scripts.  Please help!!

victor gavilan

unread,
Aug 16, 2018, 7:34:15 AM8/16/18
to yui-support
Reply all
Reply to author
Forward
0 new messages