Vulnerable jquery library
Posted: Thu Dec 03, 2020 2:05 am
jquery-1.11.2.min.js is included when accessing nagios XI at https://<ip address>. How to change it to use jquery 3.x or prevent it to load in order to address jquery 1.x vulnerability? Nagios XI version is 5.7.3.
Pls also advise how to change ALL other web pages of XI web interface to use 3.x if any.
<head>
<title>Nagios XI</title>
<meta name="ROBOTS" content="NOINDEX, NOFOLLOW">
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<link rel="shortcut icon" href="/nagiosxi/images/favicon.ico" type="image/ico">
<LINK REL='stylesheet' TYPE='text/css' HREF='/nagiosxi/includes/css/bootstrap.3.min.css'>
<LINK REL='stylesheet' TYPE='text/css' HREF='/nagiosxi/includes/css/base.css'>
<LINK REL='stylesheet' TYPE='text/css' HREF='/nagiosxi/includes/css/themes/modern.css'>
<script type='text/javascript' src='/nagiosxi/includes/js/jquery/jquery-1.11.2.min.js'></script>
<script type='text/javascript' src='/nagiosxi/includes/js/jquery/jquery-migrate-1.4.1.min.js'></script>
<script type='text/javascript' src='/nagiosxi/includes/js/core.js'></script>
</head>
Pls also advise how to change ALL other web pages of XI web interface to use 3.x if any.
<head>
<title>Nagios XI</title>
<meta name="ROBOTS" content="NOINDEX, NOFOLLOW">
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<link rel="shortcut icon" href="/nagiosxi/images/favicon.ico" type="image/ico">
<LINK REL='stylesheet' TYPE='text/css' HREF='/nagiosxi/includes/css/bootstrap.3.min.css'>
<LINK REL='stylesheet' TYPE='text/css' HREF='/nagiosxi/includes/css/base.css'>
<LINK REL='stylesheet' TYPE='text/css' HREF='/nagiosxi/includes/css/themes/modern.css'>
<script type='text/javascript' src='/nagiosxi/includes/js/jquery/jquery-1.11.2.min.js'></script>
<script type='text/javascript' src='/nagiosxi/includes/js/jquery/jquery-migrate-1.4.1.min.js'></script>
<script type='text/javascript' src='/nagiosxi/includes/js/core.js'></script>
</head>