Mitigating a vulnerable jQuery 1.12.4 library
RICOH ProcessDirector bundles a vulnerable version of jQuery (1.12.4) with RicohPDFPrinter. Use this procedure
to remove the vulnerable files and mitigate the vulnerability.
- Linux:
/opt/infoprint/ippd/pc
- Take a backup or snapshot of your system before installing any features.
- Install the updated features:
- Start RICOH ProcessDirector and check the Features page to verify that the latest versions are deployed.
- Identify and remove these jQuery library files:
/opt/infoprint/ippd/pc/ws/webapps/printing/installableOptionsTool/common/jquery/slickGrid/2.4.32/lib/jquery-1.12.4.min.js/opt/infoprint/ippd/pc/ws/webapps/printing/importerTool/common/jquery/slickGrid/2.4.32/lib/jquery-1.12.4.min.js
Run these commands to remove the files:
rm "/opt/infoprint/ippd/pc/ws/webapps/printing/installableOptionsTool/common/jquery/slickGrid/2.4.32/lib/jquery-1.12.4.min.js"
rm "/opt/infoprint/ippd/pc/ws/webapps/printing/importerTool/common/jquery/slickGrid/2.4.32/lib/jquery-1.12.4.min.js"
- You do not need to restart RICOH ProcessDirector after removing the files.
- Optional: If you created any custom PDF printers (you imported a printer GPZ file), clear your browser cache.