From: Jean-Philippe Lang Date: Sat, 7 Apr 2018 08:08:43 +0000 (+0000) Subject: Merged r17272 into 3.3-stable (#26857). X-Git-Tag: 3.3.7~5 X-Git-Url: https://source.dussan.org/?a=commitdiff_plain;h=e0fbb6f12752faa4f7a3d4c714691f2963f6cf10;p=redmine.git Merged r17272 into 3.3-stable (#26857). git-svn-id: http://svn.redmine.org/redmine/branches/3.3-stable@17274 e93f8b46-1217-0410-a6f0-8f06a7374b81 --- diff --git a/public/javascripts/application.js b/public/javascripts/application.js index b3037027e..a1beea17a 100644 --- a/public/javascripts/application.js +++ b/public/javascripts/application.js @@ -1,6 +1,13 @@ /* Redmine - project management software Copyright (C) 2006-2016 Jean-Philippe Lang */ +/* Fix for CVE-2015-9251, to be removed with JQuery >= 3.0 */ +$.ajaxPrefilter(function (s) { + if (s.crossDomain) { + s.contents.script = false; + } +}); + function checkAll(id, checked) { $('#'+id).find('input[type=checkbox]:enabled').prop('checked', checked); }