We use cookies to improve your experience. No personal information is gathered and we don't serve ads. Cookies Policy.

ExpressionEngine Logo ExpressionEngine
Features Pricing Support Find A Developer
Partners Upgrades
Blog Add-Ons Learn
Docs Forums University
Log In or Sign Up
Log In Sign Up
ExpressionEngine Logo
Features Pro new Support Find A Developer
Partners Upgrades
Blog Add-Ons Learn
Docs Forums University Blog
  • Home
  • Forums

Jquery 2.2.4 vulnerability

Feature Requests

agilepixel's avatar
agilepixel
3 posts
6 years ago
agilepixel's avatar agilepixel

We’re conducting a security audit of our site and found that Expression Engine is running jQuery 2.2.4 (expression engine 4) this version of jQuery has known security issues and the recommendation is to move to the latest version of jQuery 3.3.1

Is it possible to simply update to 3.3.1 safely or is there an upcoming release of EE4 which will include the latest version of jQuery?

       
Derek Jones's avatar
Derek Jones
7,561 posts
6 years ago
Derek Jones's avatar Derek Jones

jQuery is only used with ExpressionEngine in its own control panel, and its version is maintained by the app; you cannot update or replace those libraries. It may cause the control panel to not function properly and would be overwritten by the shipped assets when you performed a software update anyway.

Most jQuery vulnerabilities require some very specific context to exploit that typically isn’t applicable within how ExpressionEngine uses jQuery, or is irrelevant. If you are aware of a jQuery vulnerability that is exploitable within the ExpressionEngine control panel, please email the details to [email protected] and we will address it immediately. Thanks!

       

Reply

Sign In To Reply

ExpressionEngine Home Features Pro Contact Version Support
Learn Docs University Forums
Resources Support Add-Ons Partners Blog
Privacy Terms Trademark Use License

Packet Tide owns and develops ExpressionEngine. © Packet Tide, All Rights Reserved.