blob: bcd44e27d3cc3871c91793920be7c8612784865f (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
|
< thm> joeyh: ping
< thm> can you update the embedded jquery-ui? (for cve
2010-5312, and/or 2012-6662)
I'll do this next time I spend some time on ikiwiki unless Joey or
Amitai gets there first.
It doesn't look as though we actually use the vulnerable functionality.
--[[smcv]]
> This is more complicated than it looked at first glance because both
> jquery and jquery-ui have broken API since the version we embed,
> and we also ship other jquery plugins for [[plugins/attachment]].
> Perhaps someone who knows jquery could check compatibility and
> propose a branch? --[[smcv]]
|