Not planned
Description
The version of jquery in godoc is susceptible to a security vulnerability.
Metadata
Metadata
Assignees
Labels
Type
Projects
Relationships
Development
No branches or pull requests
The version of jquery in godoc is susceptible to a security vulnerability.
Activity
toothrot commentedon Jun 12, 2020
/cc @dmitshur
dmitshur commentedon Jun 12, 2020
Thanks for the report.
The
godoc
command does not have code paths that involve passing HTML from untrusted sources, so I don't believe this is a security issue. If you think I'm missing something, please use the "Flagging Existing Issues as Security-related" process described at https://golang.org/security.It can still be updated to a newer version.
[-]x/tools/cmd/godoc: jquery version needs to be upgraded[/-][+]x/tools/cmd/godoc: jquery can be updated to a newer version[/+]l-lindsay commentedon Mar 9, 2022
Any intention on upgrading jquery to a later version? Seeing this issue pop up in a scan.
Brookke commentedon Mar 18, 2022
Looks like there's a fix for this awaiting review: golang/tools#250
bcmills commentedon Dec 9, 2022
(CC @golang/security)
gmonni commentedon Dec 12, 2022
Hello would be possible upgrading jquery to 3.51. Security scanners identify the following vulnerabilities re jquery version currently in use?

14 remaining items