Details

    • Type: Enhancement
    • Status: Closed
    • Priority: Medium
    • Resolution: Done
    • Component/s: BenAdmin
    • Labels:
      None
    • Module:
      BenAdmin - Security
    • Reported by:
      Support
    • Item State:
      Production Complete - Closed
    • Issue Importance:
      Must Have

      Description

      Impact
      JQuery version 1.7.1 is vulnerable to an issue which that misinterprets selectors as HTML. Depending on the implementation, this misrepresentation could aid attackers in discovering or exploiting Cross-Site Scripting (XSS) attacks.

      Page Impacted
      https://www.workterra.net/BenAdmin/bundles/JQuery?v=GDyIzexPmDiBJ0URdNIHxEAx0xoaoH0x3SEjitOpW441

      Verification and Attack Information
      Praetorian confirmed this finding by looking up known exploits for jQuery libraries that the application leveraged.

      Recommendation
      Update jQuery libraries to the most recent version.

        Attachments

          Issue Links

            Activity

            vijayendra Vijayendra Shinde (Inactive) created issue -
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Field Original Value New Value
            Status New Request [ 10029 ] Pending for Approval [ 10002 ]
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Status Pending for Approval [ 10002 ] Approved for Development [ 10003 ]
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Status Approved for Development [ 10003 ] In Development [ 10007 ]
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Assignee Niteen Surwase [ niteen.surwase ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Link This issue relates to ST-236 [ ST-236 ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Developer Niteen Surwase [ niteen.surwase ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Link This issue relates to WT-3433 [ WT-3433 ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Link This issue relates to WT-3381 [ WT-3381 ]
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Link This issue relates to ST-243 [ ST-243 ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Link This issue relates to WT-3486 [ WT-3486 ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Link This issue relates to WT-3231 [ WT-3231 ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Link This issue relates to WT-3342 [ WT-3342 ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Link This issue relates to WT-3230 [ WT-3230 ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Link This issue relates to WT-3506 [ WT-3506 ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Assignee Niteen Surwase [ niteen.surwase ] Deepali Tidke [ deepalit ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Item State Parent values: Development(10200)Level 1 values: In Progress(10206) Parent values: LB QA(10201)
            deepalit Deepali Tidke (Inactive) made changes -
            Assignee Deepali Tidke [ deepalit ] Hrishikesh Deshpande [ hrishikesh.deshpande ]
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) made changes -
            Status In Development [ 10007 ] Local Testing [ 10200 ]
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) made changes -
            Item State Parent values: LB QA(10201) Parent values: Stage QA(10202)Level 1 values: In Testing(10214)
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) made changes -
            Status Local Testing [ 10200 ] Pending for Stage Approval [ 10300 ]
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) made changes -
            Status Pending for Stage Approval [ 10300 ] Approved for Stage [ 10030 ]
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) made changes -
            Status Approved for Stage [ 10030 ] Stage Testing [ 10201 ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Link This issue relates to WT-3606 [ WT-3606 ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Item State Parent values: Stage QA(10202)Level 1 values: In Testing(10214) Parent values: Stage QA(10202)Level 1 values: Ready for Production(10217)
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Item State Parent values: Stage QA(10202)Level 1 values: Ready for Production(10217) Parent values: Production QA(10203)Level 1 values: Production Deployed(10221)
            ashwin.wankhede Ashwin Wankhede (Inactive) made changes -
            Item State Parent values: Production QA(10203)Level 1 values: Production Deployed(10221) Parent values: Stage QA(10202)Level 1 values: Stage Deployed(11602)
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) made changes -
            Item State Parent values: Stage QA(10202)Level 1 values: Stage Deployed(11602) Parent values: Production QA(10203)Level 1 values: In Testing(10218)
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) made changes -
            Status Stage Testing [ 10201 ] Pending for Production Approval [ 10301 ]
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) made changes -
            Status Pending for Production Approval [ 10301 ] Approved for production [ 10034 ]
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) made changes -
            Status Approved for production [ 10034 ] Production Testing [ 10202 ]
            ashwin.wankhede Ashwin Wankhede (Inactive) made changes -
            Item State Parent values: Production QA(10203)Level 1 values: In Testing(10218) Parent values: Production QA(10203)Level 1 values: Production Deployed(10221)
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) made changes -
            Assignee Hrishikesh Deshpande [ hrishikesh.deshpande ] Niteen Surwase [ niteen.surwase ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Assignee Niteen Surwase [ niteen.surwase ] Hrishikesh Deshpande [ hrishikesh.deshpande ]
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) made changes -
            Item State Parent values: Production QA(10203)Level 1 values: Production Deployed(10221) Parent values: Production Complete(10222)Level 1 values: Closed(10223)
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) made changes -
            Resolution Fixed [ 1 ]
            Status Production Testing [ 10202 ] Production Complete [ 10028 ]
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) made changes -
            Status Production Complete [ 10028 ] Closed [ 6 ]

              People

              Assignee:
              hrishikesh.deshpande Hrishikesh Deshpande (Inactive)
              Reporter:
              vijayendra Vijayendra Shinde (Inactive)
              Developer:
              Niteen Surwase (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved: