Skip to content

Conversation

georgeliaw
Copy link

Description

Picking up Bootstrap 3.4.0 to fix an XSS vulnerability found in 3.3.7
refs #6178

@georgeliaw
Copy link
Author

@carltongibson fyi. Let me know if there are any additional actions.

@carltongibson
Copy link
Collaborator

No diff to the CSS?

@georgeliaw
Copy link
Author

@carltongibson Completely forgot about the CSS. They should be added now.
The diff to bootstrap-theme.min.css is weird though, it doesn't even match the old 3.3.7 upstream: https://github.com/twbs/bootstrap/blob/v3.3.7/dist/css/bootstrap-theme.min.css
Not entirely sure what's going on there.

@lovelydinosaur lovelydinosaur mentioned this pull request Jan 16, 2019
17 tasks
@lovelydinosaur
Copy link
Contributor

Resolving this in #6405, so that I can ensure I've downloaded the minified JS myself, since it's otherwise unreviewable. Thanks for progressing this!

@georgeliaw georgeliaw deleted the bootstrap-xss-fix branch January 23, 2019 22:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants