]> Cypherpunks repositories - gostls13.git/commit
[release-branch.go1.19] html/template: handle all JS whitespace characters
authorRoland Shoemaker <bracewell@google.com>
Tue, 11 Apr 2023 15:27:43 +0000 (16:27 +0100)
committerCarlos Amedee <carlos@golang.org>
Tue, 2 May 2023 16:35:20 +0000 (16:35 +0000)
commitce7bd33345416e6d8cac901792060591cafc2797
treef4997e2bd4292d4b4f193d7e105f44b9c0c8be11
parente49282327b05192e46086bf25fd3ac691205fe80
[release-branch.go1.19] html/template: handle all JS whitespace characters

Rather than just a small set. Character class as defined by \s [0].

Thanks to Juho Nurminen of Mattermost for reporting this.

For #59721
Fixes  #59813
Fixes CVE-2023-24540

[0] https://developer.mozilla.org/en-US/docs/Web/JavaScript/Guide/Regular_Expressions/Character_Classes

Change-Id: I56d4fa1ef08125b417106ee7dbfb5b0923b901ba
Reviewed-on: https://team-review.git.corp.google.com/c/golang/go-private/+/1821459
Reviewed-by: Julie Qiu <julieqiu@google.com>
Run-TryBot: Roland Shoemaker <bracewell@google.com>
Reviewed-by: Damien Neil <dneil@google.com>
Reviewed-on: https://team-review.git.corp.google.com/c/golang/go-private/+/1851497
Run-TryBot: Damien Neil <dneil@google.com>
Reviewed-by: Roland Shoemaker <bracewell@google.com>
Reviewed-on: https://go-review.googlesource.com/c/go/+/491355
Reviewed-by: Dmitri Shuralyov <dmitshur@google.com>
Reviewed-by: Carlos Amedee <carlos@golang.org>
TryBot-Bypass: Carlos Amedee <carlos@golang.org>
Run-TryBot: Carlos Amedee <carlos@golang.org>
src/html/template/js.go
src/html/template/js_test.go