You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Security issue
The jQuery libraries in use by the Nextcloud 12.0.2 are fairly outdated. The libraries (jQuery 2.1.4) dates back to April 2015. In addition, jQuery have moved to a common platform version 3.x.x, and therefore also faces the risk of no longer having available updates and security patches.
From a security perspective it appears that in the current Nextcloud 12.0.2 code, there have been applied certain changes to mitigate the currently know weaknesses in jQuery, e.g. preventing loading of scripts from external resources. Nevertheless it would be recommended to migrate the jQuery code to the new platform version 3.x.x.
Security issue
The jQuery libraries in use by the Nextcloud 12.0.2 are fairly outdated. The libraries (jQuery 2.1.4) dates back to April 2015. In addition, jQuery have moved to a common platform version 3.x.x, and therefore also faces the risk of no longer having available updates and security patches.
From a security perspective it appears that in the current Nextcloud 12.0.2 code, there have been applied certain changes to mitigate the currently know weaknesses in jQuery, e.g. preventing loading of scripts from external resources. Nevertheless it would be recommended to migrate the jQuery code to the new platform version 3.x.x.
Examples of outdated jQuery libraries:
Proposed solution
Implement automatic pulling of the latest available version of jQuery before releasing a new version of nextcloud/server
The text was updated successfully, but these errors were encountered: