Reported vulnerability in hippo-addon-2fa-duosecurity related to embedded jquery
Issue date: 27-10-2020Affects versions: 14.2, 13.4, 12.6
Issue ID: SECURITY-108
Affected Product Version(s)
14.2.2, 13.4.3, 12.6.10 (and previous patch releases)
Severity
low
Description
The version of jquery embedded within the Duo Security web integration used for the Enterprise 2-factor-authentication addon had several reported vulnerabilities. There's no indication that these vulnerabilities were exploitable in this context, and this issue affects only customers that are using the 2fa addon.
See: CVE-2011-4969 and CVE-2012-6708
The Duo Security integration has now been updated across all our latest supported versions: 14.3.0, 13.4.4 and 12.6.11.
Instructions
Customers are recommended to upgrade to the latest maintenance or minor releases as indicated above. This can be done by simply incrementing the version number of the parent POM for the implementation project.