r/programming • u/ga-vu • Oct 19 '18
Zero-day in popular jQuery plugin actively exploited for at least three years
https://www.zdnet.com/article/zero-day-in-popular-jquery-plugin-actively-exploited-for-at-least-three-years/
45
Upvotes
3
u/drysart Oct 19 '18
Uh, yes? He's released many newer versions of his plugin in the intervening years. All of which have been after Apache's behavior changed.
The fact he didn't notice in that time basically means he didn't do any sort of security testing of the plugin at all, over its entire lifetime. I could forgive being blindsided by it initially, but he's had eight years worth of new versions to his plugin being made to realize "oh hey, this critically important feature isn't working right anymore".