Details

    • Type: Enhancement
    • Status: Closed
    • Priority: Medium
    • Resolution: Done
    • Component/s: BenAdmin
    • Labels:
      None
    • Module:
      BenAdmin - Security
    • Reported by:
      Support
    • Item State:
      Production Complete - Closed
    • Issue Importance:
      Must Have

      Description

      Impact
      JQuery version 1.7.1 is vulnerable to an issue which that misinterprets selectors as HTML. Depending on the implementation, this misrepresentation could aid attackers in discovering or exploiting Cross-Site Scripting (XSS) attacks.

      Page Impacted
      https://www.workterra.net/BenAdmin/bundles/JQuery?v=GDyIzexPmDiBJ0URdNIHxEAx0xoaoH0x3SEjitOpW441

      Verification and Attack Information
      Praetorian confirmed this finding by looking up known exploits for jQuery libraries that the application leveraged.

      Recommendation
      Update jQuery libraries to the most recent version.

        Attachments

          Issue Links

            Activity

            vijayendra Vijayendra Shinde (Inactive) created issue -
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Field Original Value New Value
            Status New Request [ 10029 ] Pending for Approval [ 10002 ]
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Status Pending for Approval [ 10002 ] Approved for Development [ 10003 ]
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Status Approved for Development [ 10003 ] In Development [ 10007 ]
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Assignee Niteen Surwase [ niteen.surwase ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Link This issue relates to ST-236 [ ST-236 ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Developer Niteen Surwase [ niteen.surwase ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Link This issue relates to WT-3433 [ WT-3433 ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Link This issue relates to WT-3381 [ WT-3381 ]
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Link This issue relates to ST-243 [ ST-243 ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Link This issue relates to WT-3486 [ WT-3486 ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Link This issue relates to WT-3231 [ WT-3231 ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Link This issue relates to WT-3342 [ WT-3342 ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Link This issue relates to WT-3230 [ WT-3230 ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Link This issue relates to WT-3506 [ WT-3506 ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Assignee Niteen Surwase [ niteen.surwase ] Deepali Tidke [ deepalit ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Item State Parent values: Development(10200)Level 1 values: In Progress(10206) Parent values: LB QA(10201)
            Hide
            deepalit Deepali Tidke (Inactive) added a comment -

            Please look into this jira , this is parent jira for 4 attached sub jira's wherein 3 is with Aniruddha and 1 is with Priya.

            Once child jiras are closed this jira can also be closed.

            Show
            deepalit Deepali Tidke (Inactive) added a comment - Please look into this jira , this is parent jira for 4 attached sub jira's wherein 3 is with Aniruddha and 1 is with Priya. Once child jiras are closed this jira can also be closed.
            deepalit Deepali Tidke (Inactive) made changes -
            Assignee Deepali Tidke [ deepalit ] Hrishikesh Deshpande [ hrishikesh.deshpande ]
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) made changes -
            Status In Development [ 10007 ] Local Testing [ 10200 ]
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) made changes -
            Item State Parent values: LB QA(10201) Parent values: Stage QA(10202)Level 1 values: In Testing(10214)
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) made changes -
            Status Local Testing [ 10200 ] Pending for Stage Approval [ 10300 ]
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) made changes -
            Status Pending for Stage Approval [ 10300 ] Approved for Stage [ 10030 ]
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) made changes -
            Status Approved for Stage [ 10030 ] Stage Testing [ 10201 ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Link This issue relates to WT-3606 [ WT-3606 ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Item State Parent values: Stage QA(10202)Level 1 values: In Testing(10214) Parent values: Stage QA(10202)Level 1 values: Ready for Production(10217)
            Hide
            niteen.surwase Niteen Surwase (Inactive) added a comment -

            Hi Hrishikesh Deshpande

            CC: Vijayendra Shinde, Samir

            Minified version of Jquery migration file is going on production.
            Please make sure that JQuery is working all over project.

            Show
            niteen.surwase Niteen Surwase (Inactive) added a comment - Hi Hrishikesh Deshpande CC: Vijayendra Shinde , Samir Minified version of Jquery migration file is going on production. Please make sure that JQuery is working all over project.
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Item State Parent values: Stage QA(10202)Level 1 values: Ready for Production(10217) Parent values: Production QA(10203)Level 1 values: Production Deployed(10221)
            ashwin.wankhede Ashwin Wankhede (Inactive) made changes -
            Item State Parent values: Production QA(10203)Level 1 values: Production Deployed(10221) Parent values: Stage QA(10202)Level 1 values: Stage Deployed(11602)
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) made changes -
            Item State Parent values: Stage QA(10202)Level 1 values: Stage Deployed(11602) Parent values: Production QA(10203)Level 1 values: In Testing(10218)
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) made changes -
            Status Stage Testing [ 10201 ] Pending for Production Approval [ 10301 ]
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) made changes -
            Status Pending for Production Approval [ 10301 ] Approved for production [ 10034 ]
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) made changes -
            Status Approved for production [ 10034 ] Production Testing [ 10202 ]
            ashwin.wankhede Ashwin Wankhede (Inactive) made changes -
            Item State Parent values: Production QA(10203)Level 1 values: In Testing(10218) Parent values: Production QA(10203)Level 1 values: Production Deployed(10221)
            Hide
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) added a comment -

            Niteen Surwase

            At some pages we are getting below warning message. Please Check and revert JIRA to me in case this is not any issues.

            JQuery?v=ViMkAeLAhvSUBhZYWgSG5B7cvNrLv_RJneRiMf9ggoc1:1 Synchronous XMLHttpRequest on the main thread is deprecated because of its detrimental effects to the end user's experience.

            Thanks,
            Hrishikesh.

            CC : Vijayendra Shinde

            Show
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) added a comment - Niteen Surwase At some pages we are getting below warning message. Please Check and revert JIRA to me in case this is not any issues. JQuery?v=ViMkAeLAhvSUBhZYWgSG5B7cvNrLv_RJneRiMf9ggoc1:1 Synchronous XMLHttpRequest on the main thread is deprecated because of its detrimental effects to the end user's experience. Thanks, Hrishikesh. CC : Vijayendra Shinde
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) made changes -
            Assignee Hrishikesh Deshpande [ hrishikesh.deshpande ] Niteen Surwase [ niteen.surwase ]
            Hide
            niteen.surwase Niteen Surwase (Inactive) added a comment -

            Hi Hrishikesh Deshpande

            Please ignore this warning and refer following excelsheet from SVN to Ignore warning list for future
            \WT\JQuery Migration\Errors-Warnings to Ignore.xls

            CC: Vijayendra Shinde, Samir

            Show
            niteen.surwase Niteen Surwase (Inactive) added a comment - Hi Hrishikesh Deshpande Please ignore this warning and refer following excelsheet from SVN to Ignore warning list for future \WT\JQuery Migration\Errors-Warnings to Ignore.xls CC: Vijayendra Shinde , Samir
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Assignee Niteen Surwase [ niteen.surwase ] Hrishikesh Deshpande [ hrishikesh.deshpande ]
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) made changes -
            Item State Parent values: Production QA(10203)Level 1 values: Production Deployed(10221) Parent values: Production Complete(10222)Level 1 values: Closed(10223)
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) made changes -
            Resolution Fixed [ 1 ]
            Status Production Testing [ 10202 ] Production Complete [ 10028 ]
            Hide
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) added a comment -

            Verified that JQuery is working on WT production site properly. No any issue observed and additional issues are closed.

            Show
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) added a comment - Verified that JQuery is working on WT production site properly. No any issue observed and additional issues are closed.
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) made changes -
            Status Production Complete [ 10028 ] Closed [ 6 ]
            Transition Time In Source Status Execution Times
            Vijayendra Shinde (Inactive) made transition -
            New Request Pending for Approval
            9s 1
            Vijayendra Shinde (Inactive) made transition -
            Pending for Approval Approved for Development
            2s 1
            Vijayendra Shinde (Inactive) made transition -
            Approved for Development In Development
            2s 1
            Hrishikesh Deshpande (Inactive) made transition -
            In Development In LB Testing
            50d 47m 1
            Hrishikesh Deshpande (Inactive) made transition -
            In LB Testing Pending for Stage Approval
            12d 23h 49m 1
            Hrishikesh Deshpande (Inactive) made transition -
            Pending for Stage Approval Approved for Stage
            2s 1
            Hrishikesh Deshpande (Inactive) made transition -
            Approved for Stage Stage Testing
            2s 1
            Hrishikesh Deshpande (Inactive) made transition -
            Stage Testing Pending for Production Approval
            35d 19m 1
            Hrishikesh Deshpande (Inactive) made transition -
            Pending for Production Approval Approved for production
            3s 1
            Hrishikesh Deshpande (Inactive) made transition -
            Approved for production In Production Testing
            2s 1
            Hrishikesh Deshpande (Inactive) made transition -
            In Production Testing Production Complete
            1d 6h 31m 1
            Hrishikesh Deshpande (Inactive) made transition -
            Production Complete Closed
            1m 1

              People

              Assignee:
              hrishikesh.deshpande Hrishikesh Deshpande (Inactive)
              Reporter:
              vijayendra Vijayendra Shinde (Inactive)
              Developer:
              Niteen Surwase (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved: