Reported vulnerability in hippo-addon-2fa-duosecurity related to embedded jquery 

Issue date: 27-10-2020
Affects versions: 14.2, 13.4, 12.6

Issue ID: SECURITY-108

Affected Product Version(s)
14.2.2, 13.4.3, 12.6.10 (and previous patch releases)

Severity 
low

Description

The version of jquery embedded within the Duo Security web integration used for the Enterprise 2-factor-authentication addon had several reported vulnerabilities. There's no indication that these vulnerabilities were exploitable in this context, and this issue affects only customers that are using the 2fa addon.

See: CVE-2011-4969 and CVE-2012-6708

The Duo Security integration has now been updated across all our latest supported versions: 14.3.0, 13.4.4 and 12.6.11.

Instructions

Customers are recommended to upgrade to the latest maintenance or minor releases as indicated above. This can be done by simply incrementing the version number of the parent POM for the implementation project.