Jquery vulnerability - Nagios LS

This support forum board is for support questions relating to Nagios Log Server, our solution for managing and monitoring critical log data.
Locked
Techmnagioslsuser
Posts: 39
Joined: Fri Apr 02, 2021 1:17 am

Jquery vulnerability - Nagios LS

Post by Techmnagioslsuser »

Hello Team,
In vulnerability assessment for our production Nagios Log server installation , we see Jquery vulnerability.

"According to the self-reported version in the script, the version of JQuery hosted on the remote web server is greater than or equal to 1.2 and prior to 3.5.0. It is, therefore, affected by multiple cross site scripting vulnerabilities. Upgrade to JQuery version 3.5.0 or later."

Please suggest how can we upgrade the Jquery.

Thanks
ssax
Dreams In Code
Posts: 7682
Joined: Wed Feb 11, 2015 12:54 pm

Re: Jquery vulnerability - Nagios LS

Post by ssax »

Development hasn't released a version yet with jquery upgraded, there was a feature request submitted for it already but it hasn't been implemented yet.
Techmnagioslsuser
Posts: 39
Joined: Fri Apr 02, 2021 1:17 am

Re: Jquery vulnerability - Nagios LS

Post by Techmnagioslsuser »

Thanks for the update.

Do we have any tentative timeline for the upgraded version of Jquery.

Thanks
dchurch
Posts: 858
Joined: Wed Oct 07, 2020 12:46 pm
Location: Yo mama

Re: Jquery vulnerability - Nagios LS

Post by dchurch »

No we do not have a tentative timeline for getting this patch out. The patch for this has not yet been written.

It'll more-likely-than-not be included in the next release of Nagios Log Server, but there's no guarantees. We tend to prioritize security fixes. Please keep in mind that the decision to implement the fix is at the discretion of our development team based on likelihood and severity of the security flaw.

You can view a release history here to give you an idea when that will happen. Also when we release a fix, that page will mention a jquery fix in the release notes.
If you didn't get an 8% raise over the course of the pandemic, you took a pay cut.

Discussion of wages is protected speech under the National Labor Relations Act, and no employer can tell you you can't disclose your pay with your fellow employees.
Locked