Uploaded image for project: 'Hadoop YARN'
  1. Hadoop YARN
  2. YARN-11076

Upgrade jQuery version in Yarn UI2

    XMLWordPrintableJSON

Details

    • Reviewed

    Description

      UI2 uses an old jQuery version (2.1.4) which is affected by some known vulnerabilities, e.g.:

      Attached an example reproduction page:
      jquery.html
      The alert window pops with 1.8.2, or 2.1.4 but not with a 3.6.0. However, I couldn't exploit this with UI2, but I haven't tried every code path for sure.

      https://github.com/apache/hadoop/blob/trunk/hadoop-yarn-project/hadoop-yarn/hadoop-yarn-ui/src/main/webapp/bower.json

          "jquery": "2.1.4",
          "jquery-ui": "1.11.4",
      

      jQuery was upgraded already in hadoop-common:

      jquery-ui should also be upgraded to at least 1.13.0:

      Attachments

        1. jquery.html
          0.3 kB
          Tamas Domok
        2. ui2jquery.png
          67 kB
          Tamas Domok

        Issue Links

          Activity

            People

              tdomok Tamas Domok
              tdomok Tamas Domok
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 40m
                  40m