Skip to content

Patch jQuery against Prototype Pollution#3159

Closed
SoftCreatR wants to merge 1 commit into
WoltLab:5.2from
SoftCreatR:jquery-patch
Closed

Patch jQuery against Prototype Pollution#3159
SoftCreatR wants to merge 1 commit into
WoltLab:5.2from
SoftCreatR:jquery-patch

Conversation

@SoftCreatR
Copy link
Copy Markdown
Contributor

See GHSA-6c3j-c64m-qhgq

I think, patching the used lib is the best way to prevent any compatibility issues.

WSC 3.0 & 3.1 are also affected, but they're using older versions of jQuery. However, i can patch them too and create separate PRs, if you like.

@dtdesign dtdesign changed the base branch from next to master February 19, 2020 16:31
TimWolla added a commit that referenced this pull request May 16, 2020
@SoftCreatR SoftCreatR changed the base branch from master to 5.2 May 21, 2020 20:54
dtdesign added a commit that referenced this pull request May 23, 2020
@dtdesign
Copy link
Copy Markdown
Member

dtdesign commented May 23, 2020

Thanks, but I've manually backported the original fix to 3.0 and applied the changes to all subsequent trees (with the exception to the master which is implicitly fixed via #3310).

@dtdesign dtdesign closed this May 23, 2020
TimWolla added a commit that referenced this pull request Jun 22, 2020
@TimWolla TimWolla mentioned this pull request Jun 22, 2020
5 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants