•  
      request #18413 Update to DOMPurify 2.2.3
    Infos
    #18413
    Thomas Gerbet (tgerbet)
    2020-12-08 11:13
    2020-12-07 14:45
    19955
    Details
    Update to DOMPurify 2.2.3
    A security issue has been identified: https://github.com/cure53/DOMPurify/releases/tag/2.2.3
    Dependencies
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Thomas Gerbet (tgerbet)
    Closed
    2020-12-08
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2020-12-08 11:13
    Closing.

    There is still one vulnerable DOMPurify instance in the API Explorer plugin but for the vulnerability that was reported and in this context, there is no risk.
    A PR has been opened upstream to allow the upgrade anyway: https://github.com/swagger-api/swagger-ui/pull/6679

    • Status changed from Under review to Closed
    • Close date set to 2020-12-08