Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

Vulnerabilities in Versions of jQuery Libraries Used by Microsoft Dynamics 365


Introduction

Certain jQuery libraries in use by Dynamics have known vulnerabilities allowing cross-site scripting (XSS) attacks. This article addresses Dynamics use of these libraries and if these vulnerabilities are present in the latest releases for Dynamics 365 (On-Premises).

↑ Back to the top


Version Information

jQuery Libraries with identified vulnerabilities which are in use by the Microsoft Dynamics 365 (On-Premises) versions listed:

jQuery version 2.1.1
jQuery.ui version 1.8.21

Microsoft Dynamics 365 versions that use the above libraries reviewed for this vulnerability assessment:

Microsoft Dynamics 365 versions 8.2.2.0112 and above
Microsoft Dynamics CRM versions 7.1.2.1032 and above

↑ Back to the top


Vulnerability Assessment

For the versions of Dynamics 365 assessed, the out-of-the-box usage of vulnerable functions in the above libraries are safe. Although the libraries are in use depending on the exact build of the products, these known vulnerabilities cannot be used.

Microsoft Dynamics 365 is leveraging stable branch versions of jQuery, this includes 3.x, 2.x, and 1.x. While there are risks associated with specific functionality within the library, all usage of jQuery has been extensively reviewed in our Microsoft SDL process and we have ensured that vulnerable methods are not in use.  The processes that use these jQuery libraries will do so until they are made obsolete (deprecated) by the product.

↑ Back to the top


Article Info
Article ID : 4530348
Revision : 2
Created on : 11/5/2019
Published on : 11/5/2019
Exists online : False
Views : 165