Hello @ST_14485832,
Thank you for your patience.
I received the following update from our R&D team regarding your questions and concerns:
- A security assessment was performed on the bundled jquery.scrollintoview plugin. No publicly disclosed CVEs were identified for the bundled version of the plugin.
- Additionally, no publicly available security advisories or known exploit information were found during the investigation.
- A review of the implementation showed that the plugin performs only DOM traversal, viewport calculations, and scrolling operations. It does not perform dynamic code execution, script injection, network communication, deserialization, or any other operations typically associated with exploitable security vulnerabilities.
- Based on both the implementation review and publicly available information, no exploitable security vector was identified.
- The reported finding is considered an informational or compliance observation related to the age of the bundled third-party dependency, rather than a confirmed security vulnerability.
- The dependency continues to be used by the legacy Mashup Runtime, and there is currently no supported customer-side workaround available.
- Based on the findings of this investigation, no immediate remediation is required.
We hope this information helps address your concerns. If you have any additional questions, please feel free to let us know