Library DOMPurify, version 3.4.9 is vulnerable.

Open Beginner friendly
#6,624 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
64/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Quiet
Tech stack
javascript
Domain
security

Research direction

Start by tracing the bundled URL https://URL/js/chunk-2d216214.7dc70238.js back to the project's JavaScript dependency manifest and build entry point. Check how DOMPurify 3.4.9 is included, update it to 3.4.11, rebuild the bundle, and verify the generated asset no longer contains the vulnerable version.

Written by the indexing model from the issue text.

Description

defect in triage
Current Behavior

URL: https://URL/js/chunk-2d216214.7dc70238.js
Evidence:

/*! @license DOMPurify 3.4.9

Info:

Steps to Reproduce

Solutions: Upgrade to the latest version of the affected library. 3.4.11

Expected Behavior

Solutions: Upgrade to the latest version of the affected library. 3.4.11

Dependency-Track Version

5.x

Browser

Google Chrome

Checklist
Dominant language
Java
Stars
4.2k
Forks
817
Avg merge
7h 47m
Merged PRs (30d)
270

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from DependencyTrack/dependency-track

All issues in DependencyTrack/dependency-track

Similar issues

More Java issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.