[ https://issues.apache.org/jira/browse/MSKINS-175?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17468626#comment-17468626 ]
Michael Osipov commented on MSKINS-175: --------------------------------------- Did you actually check whether we are affected at all? Our jQuery is very light. Also going from 1.x to 3.x needs to evaluated what is affected here. > Upgrade to JQuery 3.6.0 in Fluido skin > -------------------------------------- > > Key: MSKINS-175 > URL: https://issues.apache.org/jira/browse/MSKINS-175 > Project: Maven Skins > Issue Type: Bug > Components: Fluido Skin > Reporter: László Langó > Priority: Critical > Labels: Securtity > > Please upgrade to JQuery 3.6.0 due to CVEs > ([CVE-2020-11022|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11022] > and > [CVE-2020-11023|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11023]) > affecting JQuery <3.5.0. -- This message was sent by Atlassian Jira (v8.20.1#820001)