Forum Discussion

GDC1-TRG-F5's avatar
GDC1-TRG-F5
Icon for Altostratus rankAltostratus
May 29, 2025

F5 Out of date jQuery bootstrap version

Is F5 affected by Out of date jQuery bootstrap version vulnerability CVE-2024-6531 and CVE-2020-11022, and can we remove bootstrap.min.js file from F5 APM.

As verified bootstrap is not part of BIG-IP third-party software matrix list

And even in Big IP version 17.x the jquery version shows as v1.10

3 Replies

  • As per K02453220 jQuery versions greater than or equal to 1.2 and before 3.5.0 is affected, and as verified the jquery version shows as v1.10 even on the latest 17.x version.

     

    So other than the mitigation mentioned in the article K02453220 is there any available fix for the same ?  

  • f51's avatar
    f51
    Icon for Cumulonimbus rankCumulonimbus

    As mentioned in that article, there’s currently no software fix or patch available for 17.x. However, you can restrict management access to trusted networks and users, as described in the article. I’m providing this information based on the article, but if you need more details, feel free to open a ticket with F5 support to get more information.