<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to fix error: Detect usage of JavaScript libraries with known vulnerabilities in AppInspect in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/How-to-fix-error-Detect-usage-of-JavaScript-libraries-with-known/m-p/618527#M10824</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am trying to fix an error in for an inherited add-on that i am maintaining.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;category&lt;/STRONG&gt;: app_cert_validation&lt;BR /&gt;&lt;STRONG&gt;description&lt;/STRONG&gt;: Detect usage of JavaScript libraries with known vulnerabilities.&lt;BR /&gt;&lt;STRONG&gt;ext_data&lt;/STRONG&gt;: { [+]&lt;BR /&gt;&lt;STRONG&gt;message_id&lt;/STRONG&gt;: 7002&lt;BR /&gt;&lt;STRONG&gt;rule_name&lt;/STRONG&gt;: Validate app certification&lt;BR /&gt;&lt;STRONG&gt;severity&lt;/STRONG&gt;: Fatal&lt;BR /&gt;&lt;STRONG&gt;solution&lt;/STRONG&gt;: 3rd party CORS request may execute parseHTML) executes scripts in event handlers jQuery before 3.4.0, as used in Drupal Backdrop CMS, and other products, mishandles jQuery.extend(true, (], ..) because of Object.prototype pollution Regex in its Query.htmlPrefilter sometimes may introduce XSS Regex in its jQuery.htmlPrefilter sometimes may introduce XSS reDOS - regular expression denial of service Regular Expression Denial of Service (ReDoS) Regular Expression Denial of Service (ReDoS) This vulnerability impacts pm (server) users of moment. js, especially if user provided locale string, eg fr is directly used to switch moment locale.&lt;BR /&gt;&lt;STRONG&gt;status&lt;/STRONG&gt;: Fail&lt;BR /&gt;&lt;STRONG&gt;sub_category&lt;/STRONG&gt;: Checks related to JavaScript usage&lt;/P&gt;&lt;P&gt;I checked some community questions, one of the &lt;A title="Solved: How to fix AppInspect check_for_vulnerable_javascr... - Splunk Community " href="https://community.splunk.com/t5/Building-for-the-Splunk-Platform/How-to-fix-AppInspect-check-for-vulnerable-javascript-library/m-p/587702" target="_blank" rel="noopener"&gt;answer&lt;/A&gt; mentions the below fix.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/AddonBuilder/latest/UserGuide/Importandexport" target="_self" rel="nofollow noopener noreferrer"&gt;Export&lt;/A&gt; the app from any Add-on Builder&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/AddonBuilder/latest/UserGuide/Importandexport" target="_self" rel="nofollow noopener noreferrer"&gt;Import&lt;/A&gt; the app into Add-on Builder v4.1.0 or newer&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/AddonBuilder/latest/UserGuide/Validate#Download_the_add-on_package" target="_self" rel="nofollow noopener noreferrer"&gt;Download&lt;/A&gt; the app packaged from Add-on Builder v4.1.0 or newer&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I don't have the original app export and cannot import that to new AOB. I tried importing a tgz file but that gives an error.&lt;/P&gt;&lt;P&gt;Is there any other way I can fix this or something else i can try?&lt;/P&gt;</description>
    <pubDate>Thu, 27 Oct 2022 06:15:51 GMT</pubDate>
    <dc:creator>Shukran</dc:creator>
    <dc:date>2022-10-27T06:15:51Z</dc:date>
    <item>
      <title>How to fix error: Detect usage of JavaScript libraries with known vulnerabilities in AppInspect</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/How-to-fix-error-Detect-usage-of-JavaScript-libraries-with-known/m-p/618527#M10824</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am trying to fix an error in for an inherited add-on that i am maintaining.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;category&lt;/STRONG&gt;: app_cert_validation&lt;BR /&gt;&lt;STRONG&gt;description&lt;/STRONG&gt;: Detect usage of JavaScript libraries with known vulnerabilities.&lt;BR /&gt;&lt;STRONG&gt;ext_data&lt;/STRONG&gt;: { [+]&lt;BR /&gt;&lt;STRONG&gt;message_id&lt;/STRONG&gt;: 7002&lt;BR /&gt;&lt;STRONG&gt;rule_name&lt;/STRONG&gt;: Validate app certification&lt;BR /&gt;&lt;STRONG&gt;severity&lt;/STRONG&gt;: Fatal&lt;BR /&gt;&lt;STRONG&gt;solution&lt;/STRONG&gt;: 3rd party CORS request may execute parseHTML) executes scripts in event handlers jQuery before 3.4.0, as used in Drupal Backdrop CMS, and other products, mishandles jQuery.extend(true, (], ..) because of Object.prototype pollution Regex in its Query.htmlPrefilter sometimes may introduce XSS Regex in its jQuery.htmlPrefilter sometimes may introduce XSS reDOS - regular expression denial of service Regular Expression Denial of Service (ReDoS) Regular Expression Denial of Service (ReDoS) This vulnerability impacts pm (server) users of moment. js, especially if user provided locale string, eg fr is directly used to switch moment locale.&lt;BR /&gt;&lt;STRONG&gt;status&lt;/STRONG&gt;: Fail&lt;BR /&gt;&lt;STRONG&gt;sub_category&lt;/STRONG&gt;: Checks related to JavaScript usage&lt;/P&gt;&lt;P&gt;I checked some community questions, one of the &lt;A title="Solved: How to fix AppInspect check_for_vulnerable_javascr... - Splunk Community " href="https://community.splunk.com/t5/Building-for-the-Splunk-Platform/How-to-fix-AppInspect-check-for-vulnerable-javascript-library/m-p/587702" target="_blank" rel="noopener"&gt;answer&lt;/A&gt; mentions the below fix.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/AddonBuilder/latest/UserGuide/Importandexport" target="_self" rel="nofollow noopener noreferrer"&gt;Export&lt;/A&gt; the app from any Add-on Builder&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/AddonBuilder/latest/UserGuide/Importandexport" target="_self" rel="nofollow noopener noreferrer"&gt;Import&lt;/A&gt; the app into Add-on Builder v4.1.0 or newer&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/AddonBuilder/latest/UserGuide/Validate#Download_the_add-on_package" target="_self" rel="nofollow noopener noreferrer"&gt;Download&lt;/A&gt; the app packaged from Add-on Builder v4.1.0 or newer&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I don't have the original app export and cannot import that to new AOB. I tried importing a tgz file but that gives an error.&lt;/P&gt;&lt;P&gt;Is there any other way I can fix this or something else i can try?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2022 06:15:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/How-to-fix-error-Detect-usage-of-JavaScript-libraries-with-known/m-p/618527#M10824</guid>
      <dc:creator>Shukran</dc:creator>
      <dc:date>2022-10-27T06:15:51Z</dc:date>
    </item>
  </channel>
</rss>

