Prototype CVE - update prototype.js #429
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Prototype is not being developed/released any more, but there is a fix for the CVE detailed in: prototypejs/prototype#349
I don't think that this CVE is 'dangerous' in relation to the regular EPrints codebase, but it does get flagged by scanning services.
The version string
1.7.3.1-eprintshas been invented for our purposes. It is used by prototype when constructing XMLHttpRequest headers.NB There are also other things that were committed to the prototype master branch since the 1.7.3 release, but I don't think it's worth doing anything with these, as EPrints will not rely on Prototype in the future.