Cross-Site Scripting in jQuery before 3.4.0

Tue. 7th May, 2019

It has been discovered that 3rd party library jQuery bundled with TYPO3 is vulnerable to cross-site scripting through prototype pollution.


This is a companion discussion topic for the original entry at https://typo3.org/article/typo3-psa-2019-004