Skip to content

Commit d68f67b

Browse files
authored
CVE-2024-38999 requirejs v2.3.6 was discovered to contain a prototype pollution
CVE-2024-38999 requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties
1 parent 5ac80c3 commit d68f67b

File tree

5 files changed

+6
-6
lines changed

5 files changed

+6
-6
lines changed

commons/selfservice/example-ui/src/main/resources/index.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@
2121
<div id="dialogs"></div>
2222
<footer id="footer" class="footer"></footer>
2323

24-
<script data-main="main" src="libs/requirejs-2.1.14-min.js"></script>
24+
<script data-main="main" src="libs/requirejs-2.3.7-min.js"></script>
2525

2626
</body>
2727
</html>

commons/selfservice/example/src/license/THIRD-PARTY.properties

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@ org.forgerock.commons.ui.libs--i18next--1.7.3=123
2828
org.forgerock.commons.ui.libs--jquery--2.1.1=123
2929
org.forgerock.commons.ui.libs--js2form--2.0=123
3030
org.forgerock.commons.ui.libs--moment--2.8.1=123
31-
org.forgerock.commons.ui.libs--requirejs--2.1.14=123
31+
org.forgerock.commons.ui.libs--requirejs--2.3.7=123
3232
org.forgerock.commons.ui.libs--spin--2.0.1=123
3333
org.forgerock.commons.ui.libs--titatoggle--1.2.6=123
3434
org.forgerock.commons.ui.libs--xdate--0.8=123

ui/mock/src/main/resources/index.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@
2323
<div id="dialogs"></div>
2424
<footer id="footer" class="footer text-muted"></footer>
2525

26-
<script data-main="main" src="libs/requirejs-2.1.14-min.js"></script>
26+
<script data-main="main" src="libs/requirejs-2.3.7-min.js"></script>
2727

2828
</body>
2929
</html>

ui/mock/src/test/qunit/index.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@
2727
<script src="../www/libs/qunit-2.20.1.js"></script>
2828
<script>QUnit.config.autostart = false;</script>
2929

30-
<script data-main="testRunner" src="../www/libs/requirejs-2.1.14-min.js"></script>
30+
<script data-main="testRunner" src="../www/libs/requirejs-2.3.7-min.js"></script>
3131
<script>define('qunit', function () { return QUnit; });</script>
3232
</body>
3333
</html>

ui/pom.xml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -229,7 +229,7 @@
229229
<artifactItem>
230230
<groupId>org.openidentityplatform.commons.ui.libs</groupId>
231231
<artifactId>requirejs</artifactId>
232-
<version>2.1.14</version>
232+
<version>2.3.7</version>
233233
<classifier>min</classifier>
234234
<packaging>js</packaging>
235235
<downloadUrl>https://cdnjs.cloudflare.com/ajax/libs/require.js/{version}/require.{classifier}.{packaging}</downloadUrl>
@@ -606,7 +606,7 @@
606606
<dependency>
607607
<groupId>org.openidentityplatform.commons.ui.libs</groupId>
608608
<artifactId>requirejs</artifactId>
609-
<version>2.1.14</version>
609+
<version>2.3.7</version>
610610
<classifier>min</classifier>
611611
<type>js</type>
612612
</dependency>

0 commit comments

Comments
 (0)