Forum Discussion
F5 Out of date jQuery bootstrap version
Is F5 affected by Out of date jQuery bootstrap version vulnerability CVE-2024-6531 and CVE-2020-11022, and can we remove bootstrap.min.js file from F5 APM.
As verified bootstrap is not part of BIG-IP third-party software matrix list
And even in Big IP version 17.x the jquery version shows as v1.10
3 Replies
- f51
Cumulonimbus
I have searched in our F5 articles regarding - CVE-2020-11022 and found the below
K02453220: jQuery vulnerability CVE-2020-11022 - Restrict management access
- GDC1-TRG-F5
Altostratus
As per K02453220 jQuery versions greater than or equal to 1.2 and before 3.5.0 is affected, and as verified the jquery version shows as v1.10 even on the latest 17.x version.
So other than the mitigation mentioned in the article K02453220 is there any available fix for the same ?
- f51
Cumulonimbus
As mentioned in that article, there’s currently no software fix or patch available for 17.x. However, you can restrict management access to trusted networks and users, as described in the article. I’m providing this information based on the article, but if you need more details, feel free to open a ticket with F5 support to get more information.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com