<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security vulnerabilities in Qlik Sense' AngularJS in App Development</title>
    <link>https://community.qlik.com/t5/App-Development/Security-vulnerabilities-in-Qlik-Sense-AngularJS/m-p/1572169#M41695</link>
    <description>&lt;P&gt;Qlik Sense Server November 2018 is still using Angular 1.5.8.&amp;nbsp; A bit of disappointment her.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Qlik Sense Desktop would most likely have the exact same versions of Angular, and vulnerabilities.&lt;/P&gt;&lt;P&gt;But the question is if it matters.&amp;nbsp; Are there anyone else than yourself using your Sense Desktop?&lt;BR /&gt;The vulnerabilities are mainly cross-site-scripting attacks.&lt;/P&gt;</description>
    <pubDate>Tue, 23 Apr 2019 14:33:22 GMT</pubDate>
    <dc:creator>vegard_bakke</dc:creator>
    <dc:date>2019-04-23T14:33:22Z</dc:date>
    <item>
      <title>Security vulnerabilities in Qlik Sense' AngularJS</title>
      <link>https://community.qlik.com/t5/App-Development/Security-vulnerabilities-in-Qlik-Sense-AngularJS/m-p/27456#M1869</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Qlik Sense is using AngualrJS 1.5.8, which has four known security vulnerabilities:&lt;/P&gt;&lt;P&gt;* &lt;A href="https://snyk.io/test/npm/angular/1.5.8?severity=high&amp;amp;severity=medium&amp;amp;severity=low" title="https://snyk.io/test/npm/angular/1.5.8?severity=high&amp;amp;severity=medium&amp;amp;severity=low"&gt;https://snyk.io/test/npm/angular/1.5.8?severity=high&amp;amp;severity=medium&amp;amp;severity=low&lt;/A&gt;‌&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It mentions:&lt;/P&gt;&lt;P&gt;* Content security policy bypass&lt;/P&gt;&lt;P&gt;* Cross-site scripting (x2)&lt;/P&gt;&lt;P&gt;* JSONP callback attack&lt;/P&gt;&lt;P&gt;with Medium severity.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone know if Qlik Sense is also vulnerable to this attacks, or if Qlik has fixed them in their released version of AngularJS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 15:20:03 GMT</pubDate>
      <guid>https://community.qlik.com/t5/App-Development/Security-vulnerabilities-in-Qlik-Sense-AngularJS/m-p/27456#M1869</guid>
      <dc:creator>vegard_bakke</dc:creator>
      <dc:date>2018-04-12T15:20:03Z</dc:date>
    </item>
    <item>
      <title>Re: Security vulnerabilities in Qlik Sense' AngularJS</title>
      <link>https://community.qlik.com/t5/App-Development/Security-vulnerabilities-in-Qlik-Sense-AngularJS/m-p/27457#M1870</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for raising this question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is in our plans to update angularjs to a newer version. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Apr 2018 14:52:11 GMT</pubDate>
      <guid>https://community.qlik.com/t5/App-Development/Security-vulnerabilities-in-Qlik-Sense-AngularJS/m-p/27457#M1870</guid>
      <dc:creator>iue</dc:creator>
      <dc:date>2018-04-16T14:52:11Z</dc:date>
    </item>
    <item>
      <title>Re: Security vulnerabilities in Qlik Sense' AngularJS</title>
      <link>https://community.qlik.com/t5/App-Development/Security-vulnerabilities-in-Qlik-Sense-AngularJS/m-p/27458#M1871</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hoping for June 2018 release, according to Qlik Support. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(There are a few backwards compatibility issues with the newer angular, apperently. &lt;IMG src="https://community.qlik.com/legacyfs/online/emoticons/happy.png" /&gt; )&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Apr 2018 16:22:29 GMT</pubDate>
      <guid>https://community.qlik.com/t5/App-Development/Security-vulnerabilities-in-Qlik-Sense-AngularJS/m-p/27458#M1871</guid>
      <dc:creator>vegard_bakke</dc:creator>
      <dc:date>2018-04-16T16:22:29Z</dc:date>
    </item>
    <item>
      <title>Re: Security vulnerabilities in Qlik Sense' AngularJS</title>
      <link>https://community.qlik.com/t5/App-Development/Security-vulnerabilities-in-Qlik-Sense-AngularJS/m-p/27459#M1872</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any update on this?&amp;nbsp; Doesn't look like AngularJS was upgraded in June 2018 release of Qlik Sense.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Aug 2018 17:22:49 GMT</pubDate>
      <guid>https://community.qlik.com/t5/App-Development/Security-vulnerabilities-in-Qlik-Sense-AngularJS/m-p/27459#M1872</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2018-08-21T17:22:49Z</dc:date>
    </item>
    <item>
      <title>Re: Security vulnerabilities in Qlik Sense' AngularJS</title>
      <link>https://community.qlik.com/t5/App-Development/Security-vulnerabilities-in-Qlik-Sense-AngularJS/m-p/27460#M1873</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kevin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The September18-release will include an upgrade to AngularJS 1.6.9. Our plan is to continue to upgrade AngularJS, so we always are on the latest 1.X version. Next planned upgrade is 1.7.X.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if you have other questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Aug 2018 06:54:11 GMT</pubDate>
      <guid>https://community.qlik.com/t5/App-Development/Security-vulnerabilities-in-Qlik-Sense-AngularJS/m-p/27460#M1873</guid>
      <dc:creator>iue</dc:creator>
      <dc:date>2018-08-23T06:54:11Z</dc:date>
    </item>
    <item>
      <title>Re: Security vulnerabilities in Qlik Sense' AngularJS</title>
      <link>https://community.qlik.com/t5/App-Development/Security-vulnerabilities-in-Qlik-Sense-AngularJS/m-p/1528382#M37954</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Does this vulnerability affect the desktop version?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2019 13:23:06 GMT</pubDate>
      <guid>https://community.qlik.com/t5/App-Development/Security-vulnerabilities-in-Qlik-Sense-AngularJS/m-p/1528382#M37954</guid>
      <dc:creator>nob-ruin</dc:creator>
      <dc:date>2019-01-09T13:23:06Z</dc:date>
    </item>
    <item>
      <title>Re: Security vulnerabilities in Qlik Sense' AngularJS</title>
      <link>https://community.qlik.com/t5/App-Development/Security-vulnerabilities-in-Qlik-Sense-AngularJS/m-p/1528383#M37955</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Does this vulnerability affect the desktop version?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2019 13:23:35 GMT</pubDate>
      <guid>https://community.qlik.com/t5/App-Development/Security-vulnerabilities-in-Qlik-Sense-AngularJS/m-p/1528383#M37955</guid>
      <dc:creator>nob-ruin</dc:creator>
      <dc:date>2019-01-09T13:23:35Z</dc:date>
    </item>
    <item>
      <title>Re: Security vulnerabilities in Qlik Sense' AngularJS</title>
      <link>https://community.qlik.com/t5/App-Development/Security-vulnerabilities-in-Qlik-Sense-AngularJS/m-p/1572169#M41695</link>
      <description>&lt;P&gt;Qlik Sense Server November 2018 is still using Angular 1.5.8.&amp;nbsp; A bit of disappointment her.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Qlik Sense Desktop would most likely have the exact same versions of Angular, and vulnerabilities.&lt;/P&gt;&lt;P&gt;But the question is if it matters.&amp;nbsp; Are there anyone else than yourself using your Sense Desktop?&lt;BR /&gt;The vulnerabilities are mainly cross-site-scripting attacks.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2019 14:33:22 GMT</pubDate>
      <guid>https://community.qlik.com/t5/App-Development/Security-vulnerabilities-in-Qlik-Sense-AngularJS/m-p/1572169#M41695</guid>
      <dc:creator>vegard_bakke</dc:creator>
      <dc:date>2019-04-23T14:33:22Z</dc:date>
    </item>
  </channel>
</rss>

