NetTalk Central

Author Topic: IT Audit Report  (Read 1325 times)

rupertvz

  • Sr. Member
  • ****
  • Posts: 314
    • View Profile
    • Email
IT Audit Report
« on: October 21, 2022, 04:32:23 AM »
Hi Guys,

Our client raised a JQuery concern with a NetTalk Server, version 11.45.

Any advise to fix this will be appreciated,


"The remote web server is affected by multiple cross site scripting
vulnerability."   "According to the self-reported version in the script, the version of JQuery hosted on the remote web server is greater
than or equal to 1.2 and prior to 3.5.0. It is, therefore, affected by multiple cross site scripting vulnerabilities.

Upgrade to JQuery version 3.5.0 or later.

Jane

  • Sr. Member
  • ****
  • Posts: 349
  • Expert on nothing with opinions on everything.
    • View Profile
    • Email
Re: IT Audit Report
« Reply #1 on: October 21, 2022, 07:35:57 AM »
My NT 12.47 apps report 3.6.0 
console.log(jQuery().jquery);

The History in the docs says that update to 3.6.0 was as of 12.33 last December.

As Bruce often says, security is not a "one and done" affair.  I'd suggest upgrading.

Cheers,

Jane

urayoan

  • Full Member
  • ***
  • Posts: 222
    • View Profile
    • AZ Rock Radio
Re: IT Audit Report
« Reply #2 on: October 21, 2022, 12:22:13 PM »
Like Jane said, is better to upgrade and gain other security features that are included in recent versions of NetTalk than try to fix an outdated version itself.

Bruce

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 11176
    • View Profile
Re: IT Audit Report
« Reply #3 on: October 23, 2022, 11:42:05 PM »
<< Any advise to fix this will be appreciated,

update the program to use NetTalk 12.

cheers
Bruce

rupertvz

  • Sr. Member
  • ****
  • Posts: 314
    • View Profile
    • Email
Re: IT Audit Report
« Reply #4 on: October 24, 2022, 01:41:01 AM »
Hi Bruce,

Thank you, when will NetTalk 12 turn to gold release?

Bruce

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 11176
    • View Profile
Re: IT Audit Report
« Reply #5 on: October 26, 2022, 04:29:16 AM »
"gold" is a meaningless term.
NT 12 has been used in productions systems for a couple years now.

Cheers
Bruce