Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade to bootstrap 3.4.0 to fix XSS vulnerability #6368

Closed
wants to merge 2 commits into from
Closed

Upgrade to bootstrap 3.4.0 to fix XSS vulnerability #6368

wants to merge 2 commits into from

Conversation

georgeliaw
Copy link

Description

Picking up Bootstrap 3.4.0 to fix an XSS vulnerability found in 3.3.7
refs #6178

@georgeliaw
Copy link
Author

@carltongibson fyi. Let me know if there are any additional actions.

@carltongibson
Copy link
Collaborator

No diff to the CSS?

@georgeliaw
Copy link
Author

@carltongibson Completely forgot about the CSS. They should be added now.
The diff to bootstrap-theme.min.css is weird though, it doesn't even match the old 3.3.7 upstream: https://github.com/twbs/bootstrap/blob/v3.3.7/dist/css/bootstrap-theme.min.css
Not entirely sure what's going on there.

@tomchristie tomchristie mentioned this pull request Jan 16, 2019
17 tasks
@tomchristie
Copy link
Member

Resolving this in #6405, so that I can ensure I've downloaded the minified JS myself, since it's otherwise unreviewable. Thanks for progressing this!

@georgeliaw georgeliaw deleted the bootstrap-xss-fix branch January 23, 2019 22:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants