Address Jetty, jQuery, jQuery UI, and AngularJS security vulnerabilities

This article explains how to address security vulnerabilities related to Jetty, jQuery, jQuery UI, and AngularJS in Adobe Experience Manager (AEM) 6.5 On-Premise environments by upgrading to the latest service packs and reviewing custom integrations.

Description description

Environment

Adobe Experience Manager (AEM) 6.5 On-Premise (OSGi)

Symptoms

Security scan or penetration test reports CVEs for Jetty, jQuery, jQuery UI, or AngularJS in your AEM deployment.

Cause

  • Outdated versions of Jetty, jQuery, or jQuery UI included in older AEM service packs.
  • AngularJS is not included by default with AEM; vulnerabilities related to AngularJS typically originate from custom code or third-party packages.

Resolution resolution

Follow the steps below to resolve the issue.

  1. Upgrade to the latest available AEM 6.5 Service Pack and Forms Add-on (if applicable). Download the latest AEM 6.5 Service Pack from the official Adobe distribution portal. If you use AEM Forms, download the latest AEM 6.5 Forms Add-on. Follow the standard Adobe documentation to install the service pack and add-on.
  2. Verify that Jetty vulnerabilities (CVE-2023-26049, CVE-2023-26048) are addressed. These vulnerabilities are fixed in Jetty 9.4.51 and are included in recent service packs.
  3. Verify that jQuery vulnerabilities (CVE-2020-11022, CVE-2019-11358) are addressed. These vulnerabilities are addressed in recent service packs. See the relevant Adobe Knowledge Base articles.
  4. Verify that jQuery UI vulnerabilities (CVE-2022-31160, CVE-2021-41184) are addressed. These vulnerabilities are patched in jQuery UI 1.13.x and included in recent service packs.
  5. If your security scan reports AngularJS vulnerabilities (CVE-2024-21490, CVE-2022-25869), identify which custom bundle, package, or third-party integration is introducing AngularJS. AngularJS is not included with AEM by default.
  6. Search your codebase and /apps, /libs, and /etc/clientlibs for references to AngularJS libraries, such as files named angular.js or angular.min.js.
  7. Review your custom client libraries and third-party packages for AngularJS dependencies.
  8. Update any custom or third-party AngularJS libraries to a secure version as recommended in the relevant CVE advisories.
  9. If you are unable to determine the source of AngularJS, consult your development team or third-party vendors for further investigation.
  10. After upgrading and updating libraries, rerun your security scan to verify that the vulnerabilities are resolved.
recommendation-more-help
experience-cloud-kcs-help-kbarticles