? NPM Resource Changed bug PR-4.4-dev Pending

User tests: Successful: Unsuccessful:

avatar brianteeman
brianteeman
17 Nov 2023

This is a security release

Version 5.10.9 - November 15, 2023

Changed

  • Zero width no-break space (U+FEFF) characters are removed from content passed to setContent, insertContent, and resetContent APIs.
  • Zero width no-break space (U+FEFF) characters in initial content are not loaded into the editor upon initialization.

Fixed

  • Specific HTML content containing unescaped text nodes caused mXSS when using undo/redo.
  • Specific HTML content containing unescaped text nodes caused mXSS when using the getContent and setContent APIs with the format: 'raw' option, which also affected the resetContent API and the draft restoration feature of the Autosave plugin
avatar brianteeman brianteeman - open - 17 Nov 2023
avatar brianteeman brianteeman - change - 17 Nov 2023
Status New Pending
avatar joomla-cms-bot joomla-cms-bot - change - 17 Nov 2023
Category NPM Change Front End Plugins
avatar brianteeman brianteeman - change - 17 Nov 2023
The description was changed
avatar brianteeman brianteeman - edited - 17 Nov 2023
avatar brianteeman brianteeman - change - 17 Nov 2023
The description was changed
avatar brianteeman brianteeman - edited - 17 Nov 2023
avatar brianteeman
brianteeman - comment - 17 Nov 2023

Note a similar update is required for tiny6 and joomla5 but I cant create it due to this bug #42356

avatar Fedik Fedik - test_item - 21 Nov 2023 - Tested successfully
avatar Fedik
Fedik - comment - 21 Nov 2023

I have tested this item ✅ successfully on 7031c0c


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/42359.

avatar wilsonge
wilsonge - comment - 21 Nov 2023

Just noting that I see the TinyMCE6 update has been done directly with ba3fa03

avatar SniperSister SniperSister - test_item - 21 Nov 2023 - Tested successfully
avatar SniperSister
SniperSister - comment - 21 Nov 2023

I have tested this item ✅ successfully on 7031c0c


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/42359.

avatar brianteeman
brianteeman - comment - 21 Nov 2023

Just noting that I see the TinyMCE6 update has been done directly with ba3fa03

Grrh

avatar Quy Quy - change - 21 Nov 2023
Status Pending Ready to Commit
Labels Added: NPM Resource Changed PR-4.4-dev
avatar Quy
Quy - comment - 21 Nov 2023

RTC


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/42359.

avatar Quy Quy - change - 21 Nov 2023
Labels Added: ?
avatar MacJoom MacJoom - change - 23 Nov 2023
Status Ready to Commit Fixed in Code Base
Closed_Date 0000-00-00 00:00:00 2023-11-23 09:08:45
Closed_By MacJoom
Labels Added: ? bug
Removed: ?
avatar MacJoom MacJoom - close - 23 Nov 2023
avatar MacJoom MacJoom - merge - 23 Nov 2023

Add a Comment

Login with GitHub to post a comment