<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00008i0CJBCA2Okta Classic EngineAnswered2023-01-25T00:56:08.000Z2023-01-23T14:46:45.000Z2023-01-25T00:56:08.000Z
  • User16525339948075792502 (Management &amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;)

    Hi Luis,

     

    Thank you for raising this question on our community page, my name is David from Okta Support.

    At this moment the requested documentation has been removed due to it being outdated, with the following data being the only available information:

     

    The jQuery library used in Okta's sign-in widget has been upgraded to version 3.6.1.

     

    This can be validated in the Chrome browser using developer tools and entering the following command in the console: jQueryCourage.fn.jquery

     

    There are other instances of jQuery 1.12.4 pulled from the Okta CDN (not for the sign-in widget) that security scanners will find. Upon inspection of the file, customers will find that by searching for CVEs, our developers have left notes of how they fixed the file to prevent the vulnerabilty. 

     

    Respectfully,

    David Muset

    Expand Post
  • Hi David,

     

    Thanks, for quick response.

    For general knowledge these are the lines where the okta developers patched the vulnerabilities.

     

    image-20230125-004723image-20230125-004741Regards,

    Luis Bazan

    Expand Post
This question is closed.
Loading
Okta using jquery 1.12.4 in the signin widget.