JQuery 1.2 < 3.5.0 Multiple XSS #3857

Closed
opened 2025-12-29 18:31:37 +01:00 by adam · 1 comment
Owner

Originally created by @nordicmachine on GitHub (Jul 13, 2020).

We regularly scan all of our systems with Nessus and its been reporting that Netbox has jQuery 3.4.1 which according to Nessus (https://www.tenable.com/plugins/nessus/136929) and jQuery itself (https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/) is vulnerable to several XSS attacks. I haven't tried actually exploiting this in Netbox, but wanted to raise this here in case this actually affects Netbox. We're running 2.7.6 but I notice that even in master jQuery is still at 3.4.1.

Python version: 3.6.8
Netbox version: 2.7.6

I would expect to be able to scan a Netbox installation and not have any security vulnerabilities reported by Nessus. Even if this poses no issue for Netbox, this poses some difficulty for us as we have to file paperwork for any reported vulnerabilities that aren't resolved.

Apologies for this not completely confirming to the submission guide but I'm not sure how to submit a security issue as it wasn't outlined in the guide.

Originally created by @nordicmachine on GitHub (Jul 13, 2020). We regularly scan all of our systems with Nessus and its been reporting that Netbox has jQuery 3.4.1 which according to Nessus (https://www.tenable.com/plugins/nessus/136929) and jQuery itself (https://blog.jquery.com/2020/04/10/jquery-3-5-0-released/) is vulnerable to several XSS attacks. I haven't tried actually exploiting this in Netbox, but wanted to raise this here in case this actually affects Netbox. We're running 2.7.6 but I notice that even in master jQuery is still at 3.4.1. Python version: 3.6.8 Netbox version: 2.7.6 I would expect to be able to scan a Netbox installation and not have any security vulnerabilities reported by Nessus. Even if this poses no issue for Netbox, this poses some difficulty for us as we have to file paperwork for any reported vulnerabilities that aren't resolved. Apologies for this not completely confirming to the submission guide but I'm not sure how to submit a security issue as it wasn't outlined in the guide.
adam closed this issue 2025-12-29 18:31:37 +01:00
Author
Owner

@jeremystretch commented on GitHub (Jul 13, 2020):

Closing this because 1) it does not use one of the provided templates, and 2) the NetBox version cited is out of date.

@jeremystretch commented on GitHub (Jul 13, 2020): Closing this because 1) it does not use one of the provided templates, and 2) the NetBox version cited is out of date.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/netbox#3857