From bdc7d91fdd2f11f10a78ea1ea7362b0e2f789d90 Mon Sep 17 00:00:00 2001 From: Fabrizio Balliano Date: Thu, 2 Feb 2023 10:00:25 +0000 Subject: [PATCH] Fixed ReDos vulnerability in prototypejs (#3003) --- js/prototype/prototype.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/js/prototype/prototype.js b/js/prototype/prototype.js index bf2d3b3eab9..e00b2679260 100644 --- a/js/prototype/prototype.js +++ b/js/prototype/prototype.js @@ -621,7 +621,7 @@ Object.extend(String.prototype, (function() { } function stripTags() { - return this.replace(/<\w+(\s+("[^"]*"|'[^']*'|[^>])+)?(\/)?>|<\/\w+>/gi, ''); + return this.replace(/<\w+(\s+("[^"]*"|'[^']*'|[^>'"])+)?\s*("[^">]*|'[^'>])?(\/)?>|<\/\w+>/gi, ''); } function stripScripts() {