Trustwave ASV failed Scan (PCI) and Luminate Online jQuery upgrade request per listed remediation

Options
Hi,


I am wondering if anyone is encountering failed PCI scan related to jQuery version used on Luminate Online with following CVE Number:

CVE-2012-6708 

The remediation is to update to jquery version 1.9.0 or higher

CVE-2015-9251  

On it it says the remedy is to upgrade to version 3.0.0 or higher


All of the two within one report and they seem to be contradicting one another where one ask to update to 1.9.0 and one to version 3.  But to make matter worse updating from version 1 to 3 is going to break things up for sure not to mention the epic level of effort to rewrite the functionalities/plugins that otherwise is dependent on the older version and not supported by 3.


On top of that we know even without customization Blackbaud/Luminate Online is running on jQuery 1.6.4 as indicated on their modules.js component (i.e. https://secure2.convio.net/adap/js/convio/modules.js )  even though we could call / run separate jQuery version that is usually higher than Blackbaud's which is true on most our cases (we are using 1.11 or 1.12 at moment for ours)


Thoughts? ideas? or what is it that we should take to resolve the issue? Could this be a false-positive warning due to something?   We have brought it up upon to our CSM and they are still investigating.


regards,

Daniel
Tagged:

Categories