Page 1 of 1

XSS vulnerability for Primeface

Posted: 19 Apr 2017, 11:10
by sinphang
XSS vulnerability for Primeface, will this resolve in Elite version? What is the resolution for us in getting rid of XSS security vulnerability.
The version of jQuery 1.11.0 contains well-known vulnerabilities which may lead to cross-site scripting and credential/session theft. The following functions are known to be vulnerable. Can check which Primeface version will resolve this?
1) ""location.hash""
2) ""id""
3) ""class""
4) "":first""
5) ""document.referrer"""

Re: XSS vulnerability for Primeface

Posted: 20 Apr 2017, 02:22
by Melloware
You can read about this issue here:

https://github.com/primefaces/primefaces/issues/2204