Validate the Okta jQuery Library Version
Last Updated:
Overview
Security scans or penetration tests may detect older jQuery version numbers on Okta-hosted pages because the version string does not always reflect applied security patches. Okta maintains patched versions of these libraries, and administrators can validate the active jQuery version using browser developer tools.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- jQuery
Cause
Security scanning tools detect jQuery version strings on Okta-hosted pages and flag them against CVE databases such as cve.org. The version number shown by a scanner does not always reflect whether the underlying code has been patched against those CVEs.
Solution
How is the Okta jQuery library version validated?
Okta upgrades the jQuery library used in the Okta Sign-In Widget to jQuery 3.x. Validate the jQuery version in the Google Chrome browser by opening the Developer Tools and entering the following command in the Console.
jQueryCourage.fn.jquery
- Example:
Security scanners may detect other instances of jQuery 1.12.4 pulled from the Okta Content Delivery Network (CDN) for pages other than the Sign-In Widget. Upon inspection of the file, these tests reveal that Okta developers leave notes indicating how Okta addresses the vulnerability during CVE searches.
The following error may occur after running the validation command:
This error occurs because the Sign-In Widget uses the Third-Generation widget. Temporarily disable this feature to highlight the jQuery version, then follow the steps in the Enable Third Generation Sign-In Widget documentation.
The /help/login page loads an internally maintained, patched version of jQuery 1.12.4. This build addresses specific CVEs against the upstream jQuery 1.12.4 release.
- CVE-2015-9251
- CVE-2019-11358
- CVE-2020-11022
- CVE-2020-11023
