Hello everyone,
Our vulnerability scanning tool is coming back with JQuery 1.2 < 3.5.0 Multiple XSS (CVE-2020-11022) but only on our AIX servers. I'm curious if anyone seen this.
https://server1:5693/static/js/jquery.3.4.1.min.js
That .js file is in /usr/local/ncpa/listener/static/js/jquery.3.4.1.min.js on all those servers.
Looking around (googling), it looks like there is a 3.5.0 version. Would it break anything if that was upgraded?
jquery vulnerability showing on AIX
Re: jquery vulnerability showing on AIX
Hi @kbauma01,
I checked and it looks like we ship a newer version of jquery (3.5.1) with NCPA as of a while ago, I believe you should be fine to upgrade this. As always I'd recommend taking a VM snapshot before making changes.
I checked and it looks like we ship a newer version of jquery (3.5.1) with NCPA as of a while ago, I believe you should be fine to upgrade this. As always I'd recommend taking a VM snapshot before making changes.
Re: jquery vulnerability showing on AIX
Thanks @jsimon
Is there a newer NCPA agent for AIX? The one I see is 2.2.1.
Is there a newer NCPA agent for AIX? The one I see is 2.2.1.
Re: jquery vulnerability showing on AIX
We currently are not producing AIX packages for NCPA. As NCPA is maintained as open source software, you could try building a newer version in house if there are specific requirements you need to meet. Another option would be to look at migrating to NRPE, if that suits your use case better.
-
- Posts: 8
- Joined: Mon Jul 24, 2023 11:11 pm
Re: jquery vulnerability showing on AIX
Hopefully there will be AIX packages for NCPA soon. Because I am having some problems and need AIXjsimon wrote: ↑Tue Sep 10, 2024 3:02 pm We currently are not producing AIX packages for NCPA. As NCPA is maintained as open source software, you could try building a newer version in house if there are specific requirements you need to meet. Another option would be to look at migrating to NRPE, if that suits your use case betterstickman hook
Re: jquery vulnerability showing on AIX
I would also like to see a newer version of NCPA for AIX. We use the NCPA agent on all our different platforms, including AIX.
Re: jquery vulnerability showing on AIX
I'll reference my other post on this topic here: viewtopic.php?p=360003#top
Actively advancing awesome answers with ardent alliteration, aptly addressing all ambiguities. Amplify your acumen and avail our amicable assistance. Eagerly awaiting your astute assessments of our advice.