Quantcast
Channel: Issues for Drupal core
Viewing all articles
Browse latest Browse all 301855

yarn libraries using insecure versions

$
0
0

Problem/Motivation

One of our drupal site's repositories in github, that uses dependabot alerts, raised two critical security warnings in /docroot/core/yarn.lock file.

  • Terser insecure use of regular expressions before v4.8.1 and v5.14.2 leads to ReDoS. Patched version: 5.14.2
  • jQuery UI Cross-site Scripting when refreshing a checkboxradio with an HTML-like initial text label. Patched version: 1.13.2

Proposed resolution

Please, update these dependencies versions and compile the assets to remove this issue.

Thank you,


Viewing all articles
Browse latest Browse all 301855

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>