Burp Suite User Forum

Create new post

The JavaScript file 'jquery.mobile-1.4.5.min.js' includes a vulnerable version of the library

Olga | Last updated: Mar 06, 2019 09:25AM UTC

Hi all, We faced an issue from Burp Report: "Issue detail The library jquery-mobile version 1.4.5.min has known security issues. For more information, visit those websites: http://sirdarckcat.blogspot.no/2017/02/unpatched-0day-jquery-mobile-xss.html <h3>Affected versions</h3> The vulnerability is affecting all versions prior 100.0.0 (between * and 100.0.0)" But jquery-mobile version 1.4.5 is the latest released version: https://code.jquery.com/mobile/ Version number 100.0.0 looks like an error number. Is the finding - false positive or Burp issue? Thanks, Olga

PortSwigger Agent | Last updated: Mar 06, 2019 10:54AM UTC

Burp doesn't have a check for this, so I suspect this was raised by an extension. If you can share a screenshot of the advisory, this will include the extension name and we can inform the author about the typo.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.