Uploaded image for project: 'Moodle'
  1. Moodle
  2. MDL-74734

Vulnerable YUI modules in 3.17.2

XMLWordPrintable

    • Icon: Improvement Improvement
    • Resolution: Fixed
    • Icon: Minor Minor
    • 4.1.11
    • 4.0.1
    • JavaScript
    • None
    • MOODLE_400_STABLE
    • MOODLE_401_STABLE

      Hi there,

      I can see updating YUI has been discussed previously (some time ago) in https://tracker.moodle.org/browse/MDL-49535

      A recent penetration test has highlighted a few vulnerabilities with yui 3.17.2 modules such as "qs": https://snyk.io/test/npm/yui/3.17.2

      The suggested remediation is to update to yui 3.18.0, but if the modules are not used by Moodle perhaps this is not necessary? I am unsure of if Moodle HQ would have a policy regarding that so I think it's best to be safe and at least raise this tracker.

      My understanding is that YUI is in the process of being deprecated but is still used within several Moodle modules and plug-ins, so that may also be a factor in if this is worth doing.

      Let me know if you need to know anything else, please close if not needed. 

       

       

            Unassigned Unassigned
            sgodbehere Samuel Godbehere
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved:

                Error rendering 'clockify-timesheets-time-tracking-reports:timer-sidebar'. Please contact your Jira administrators.