diff options
author | Jean-Philippe Lang <jp_lang@yahoo.fr> | 2018-04-07 08:08:04 +0000 |
---|---|---|
committer | Jean-Philippe Lang <jp_lang@yahoo.fr> | 2018-04-07 08:08:04 +0000 |
commit | fc401c3ab6395c5fd77e0cec0d58ae1669ea6499 (patch) | |
tree | 76731a20657c6a76076c8e18a5196356536259e0 | |
parent | 578a9e67d3473e87e0acdeb51ab06f1a92ac0ab2 (diff) | |
download | redmine-fc401c3ab6395c5fd77e0cec0d58ae1669ea6499.tar.gz redmine-fc401c3ab6395c5fd77e0cec0d58ae1669ea6499.zip |
Merged r17272 into 3.4-stable (#26857).
git-svn-id: http://svn.redmine.org/redmine/branches/3.4-stable@17273 e93f8b46-1217-0410-a6f0-8f06a7374b81
-rw-r--r-- | public/javascripts/application.js | 7 |
1 files changed, 7 insertions, 0 deletions
diff --git a/public/javascripts/application.js b/public/javascripts/application.js index b6352fd2a..4e1b40ab8 100644 --- a/public/javascripts/application.js +++ b/public/javascripts/application.js @@ -1,6 +1,13 @@ /* Redmine - project management software Copyright (C) 2006-2017 Jean-Philippe Lang */ +/* Fix for CVE-2015-9251, to be removed with JQuery >= 3.0 */ +$.ajaxPrefilter(function (s) { + if (s.crossDomain) { + s.contents.script = false; + } +}); + function checkAll(id, checked) { $('#'+id).find('input[type=checkbox]:enabled').prop('checked', checked); } |