Bootstrap, Version 3.2.0 is Vulnerable In SP Page Builder - Question | JoomShaper

Bootstrap, Version 3.2.0 is Vulnerable In SP Page Builder

JH

Jacob Hodara

SP Page Builder 2 years ago

Hi Recently i got the notification from security Team over the sp page builder bootstrap lib is outdated and vulnerable Here is message :

/components/com_sppagebuilder/assets/js/sppagebuilder.js - The identified library bootstrap, version 3.2.0 is vulnerable. this.close)};i.VERSION="3.2.0",i.prototype.close

Is there any plan to update the Bootstrap version lib in SP Page builder 3.8.9 ?

0
26 Answers
Toufiq
Toufiq
Accepted Answer
Senior Staff 2 years ago #114323

Hi there,

I appreciate you reaching out. I sincerely apologize for this oversight. I will talk to with our developer team and let you know the update.

-Thanks

0
JH
Jacob Hodara
Accepted Answer
2 years ago #114743

Thank you Please keep updated when it will be updated/fix

0
Toufiq
Toufiq
Accepted Answer
Senior Staff 2 years ago #114765

Developer team is checking this issue. Thanks

0
JH
Jacob Hodara
Accepted Answer
2 years ago #115612

Hi Any updates from Developer team on this?

0
Toufiq
Toufiq
Accepted Answer
Senior Staff 2 years ago #115616

Please download the 3.8.10 version. Thanks

0
MR
marius van Rijnsoever
Accepted Answer
2 years ago #133770

Hi

Am getting the same vulneravility report and have Page Builder Pro 5.1.3 installed.

components/com_sppagebuilder/assets/js/sppagebuilder.js "The identified library bootstrap, version 3.2.0 is vulnerable."

Is there any fix for this? Will need to get this fixed asap as my sites need penetration testing accreditation.

Thanks, Marius

0
Toufiq
Toufiq
Accepted Answer
Senior Staff 2 years ago #133838

I have informed our team. I will get back to you soon. Thanks

0
Toufiq
Toufiq
Accepted Answer
Senior Staff 2 years ago #134086

When have you got this issue and where exactly should i check?

0
MR
marius van Rijnsoever
Accepted Answer
2 years ago #134101

Look in the js script I mentioned and search for 3.2.0, this version of bootstrap is vulnerable https://security.snyk.io/package/npm/bootstrap/3.2.0

0
Toufiq
Toufiq
Accepted Answer
Senior Staff 2 years ago #134116

Thanks

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 2 years ago #134117

@Marius - Thanks for details, I added that to our Backlog with High priority status.

Probably some old lines left from BT3 .js - that's why.

0
MR
marius van Rijnsoever
Accepted Answer
1 year ago #136993

Hi Paul

Any updates on this?

Thanks, Marius

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 1 year ago #136998

We are working to improve that. But it request time becuase it's realted with used addons.

And for sure it will be fixed in SPPB 5.1.x update.

0
VM
Vince Murphy
Accepted Answer
1 year ago #142412

Hi, I'm running SPPB 5.2.4 pro and trying to pass a security audit. It's failing due to this vunerable library (bootstrap 3.2.0). I'm wondering if there is any update on a fix for this?

Thanks....Vince

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 1 year ago #142446

Not yet. But if we know which line(s) of code makes a major problem, we can fix it sooner.

0
VM
Vince Murphy
Accepted Answer
1 year ago #142531

Hi Paul, Thanks for your quick response. The file involved is: components/com_sppagebuilder/assets/js/sppagebuilder.js There are several lines which reference version 3.2.0. Lines: 13 (this is the one reported but I imagine if this is fixed, the next line with 3.2.0 will fail) Other lines: 51, 180, 230, 449

Thanks for looking at this.

Cheers...Vince
0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 1 year ago #142532

I knew the file, but thanks for lines...

0
VM
Vince Murphy
Accepted Answer
1 year ago #143552

Hi, I'm wondering if there is any update on a fix for this vunerable library (bootstrap 3.2.0) issue. I'm trying to pass a security audit and knowing any details on fix schedule would be very helpful. Any info much appreciated.

Cheers...Vince
0
MR
marius van Rijnsoever
Accepted Answer
1 year ago #143621

Its been 8 months since it was first reported. Your best bet is to manually change the version number to pass the audit while you wait for the developers to update the library to the secure latest version (likely a long time). "bootstrap 3.2.0" was released 10 years ago, so not really a new security issue but sounds like developers don't want to update due to backward compatibilities

0
Toufiq
Toufiq
Accepted Answer
Senior Staff 1 year ago #143628

Please check this build on your staging site and let me know your issue solved or not.

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 1 year ago #143627

We have version that should fix that problem already , but I can share with @Jacob, becuase it was his topic.

If somebody else want to test it as well, please look down, to post below.

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 1 year ago #143631

@Vince, @Marius

or just replace only that file: components/com_sppagebuilder/assets/js/sppagebuilder.js

Download & unzip & FTP upload/override > sppagebuilder.zip

and make audit test again.


BTW

What tool you're using?

0
VM
Vince Murphy
Accepted Answer
1 year ago #143740

Thanks Paul. I've downloaded and installed the replacement file. I've sent it off for testing. The testing is being done by: https://www.complade.com/ using a tool they call Maple. Thanks again for your help on this, much appreciated. I'll report back with the results of the testing.

0
VM
Vince Murphy
Accepted Answer
1 year ago #143746

Hi Paul, Just heard back from the audit team and the news is good. The vulnerability issue has been resolved with the new file. Again, much appreciated.

Cheers...Vince
0
Toufiq
Toufiq
Accepted Answer
Senior Staff 1 year ago #143760

You are most welcome & Thanks.

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 1 year ago #143765

In the upcomig update we will include that updated .js file :))

Thanks for testing, sorry that it took so long from our side.

0