[R1] Nessus Network Monitor 5.13.0 Fixes One Third-party Vulnerability

Related Vulnerabilities: CVE-2020-11022   CVE-2020-11023  

Nessus Network Monitor leverages third-party software to help provide underlying functionality. One of the third-party components (jQuery) was found to contain vulnerabilities, and updated versions have been made available by the providers. Out of caution and in line with good practice, Tenable opted to upgrade the bundled jQuery components to address the potential impact of these issues. Nessus Network Monitor 5.13.0 updates jQuery to version 3.5.1 to address the identified vulnerabilities.

Synopsis

Nessus Network Monitor leverages third-party software to help provide underlying functionality. One of the third-party components (jQuery) was found to contain vulnerabilities, and updated versions have been made available by the providers.

Out of caution and in line with good practice, Tenable opted to upgrade the bundled jQuery components to address the potential impact of these issues. Nessus Network Monitor 5.13.0 updates jQuery to version 3.5.1 to address the identified vulnerabilities.

Solution

Tenable has included a fix in Nessus Network Monitor 5.13.0 to address this issue. The installation files can be obtained from the Tenable Downloads Portal (https://www.tenable.com/downloads/nessus-network-monitor).