Description
An insecure component vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. Magento 2 codebase leveraged outdated versions of JS libraries (Bootstrap, jquery, Knockout) with known security vulnerabilities.
Remediation
References
Related Vulnerabilities
Liferay Portal Insecure Default Initialization of Resource Vulnerability (CVE-2023-33949)
WordPress Plugin Konnichiwa! Membership Cross-Site Scripting (0.8.3)
WordPress Plugin Super Logos Showcase for WordPress Arbitrary File Upload (2.2)
WordPress Plugin Slider Revolution Responsive Arbitrary File Upload (3.0.95)