Nagios systems being flagged for old version of jQuery

This support forum board is for support questions relating to Nagios XI, our flagship commercial network monitoring solution.
Locked
rferebee
Posts: 733
Joined: Wed Jul 11, 2018 11:37 am

Nagios systems being flagged for old version of jQuery

Post by rferebee »

Good morning Nagios team,

Recently our Nagios hosts were flagged during a vulnerability scan for having an outdated version of jQuery installed.

'JQuery 1.2 < 3.5.0 Multiple XSS'

I'm wondering if there is anything we can do to address this, so the hosts don't keep showing up in the scans. I found another forum post where one of the Nagios support folks mentioned that XI uses two different versions of jQuery. One for the GUI (newer) and one for running reports (older).

Basically, I just need to know if we can update the version of jQuery that Nagios is using or if we need to file for an exception with our ISO.

Thank you.
benjaminsmith
Posts: 5324
Joined: Wed Aug 22, 2018 4:39 pm
Location: saint paul

Re: Nagios systems being flagged for old version of jQuery

Post by benjaminsmith »

Hi,

That's correct. There is an older version of jquery that runs in the back end to create pdfs, updating this would cause issues with reports. The newer version, 3.5.1, is used in the GUI itself.

Let me know if you have more questions.

Thanks
As of May 25th, 2018, all communications with Nagios Enterprises and its employees are covered under our new Privacy Policy.

Be sure to check out our Knowledgebase for helpful articles and solutions!
rferebee
Posts: 733
Joined: Wed Jul 11, 2018 11:37 am

Re: Nagios systems being flagged for old version of jQuery

Post by rferebee »

That's all I needed to know. Thank you very much.

You can lock this.
benjaminsmith
Posts: 5324
Joined: Wed Aug 22, 2018 4:39 pm
Location: saint paul

Re: Nagios systems being flagged for old version of jQuery

Post by benjaminsmith »

That's all I needed to know. Thank you very much.
Your welcome!

Have a great weekend.
As of May 25th, 2018, all communications with Nagios Enterprises and its employees are covered under our new Privacy Policy.

Be sure to check out our Knowledgebase for helpful articles and solutions!
Locked