Require.js Security Vulnerability
Posted: Thu May 01, 2025 5:08 am
Noticed that the last update to Flare mentioned a security patch.
Digging into that, it's an update to require.js, moving from 2.3.6 to 2.3.7
This one is bad and the vulnerability has been known since June / July of last year. I can't believe that they're only getting around to patching it now and that they haven't made more of an effort to let customers know. Until I started digging into this, I also didn't know about an earlier vulnerability: https://www.blackduck.com/blog/cyrc-adv ... ck-hub.htm
Our customers are extremely security conscious and now we're going to have egg on face as we explain this to them. I understand that security vulnerabilities happen, but I'm beyond ticked that Madcap didn't patch this one faster and that they didn't do a better job of communicating it.
Digging into that, it's an update to require.js, moving from 2.3.6 to 2.3.7
This one is bad and the vulnerability has been known since June / July of last year. I can't believe that they're only getting around to patching it now and that they haven't made more of an effort to let customers know. Until I started digging into this, I also didn't know about an earlier vulnerability: https://www.blackduck.com/blog/cyrc-adv ... ck-hub.htm
Our customers are extremely security conscious and now we're going to have egg on face as we explain this to them. I understand that security vulnerabilities happen, but I'm beyond ticked that Madcap didn't patch this one faster and that they didn't do a better job of communicating it.