4 ms·
I suspect the commit to fix is: https://github.com/facebook/react/commit/bbed0b0ee64b89353a40d6313037bbc80221bc3d https://github.com/facebook/react/commit/bbed
by benmmurphy 10mo ago
I suspect the commit to fix is:
https://github.com/facebook/react/commit/bbed0b0ee64b89353a40d6313037bbc80221bc3d https://github.com/facebook/react/commit/bbed0b0ee64b89353a4...
and it looks like its been squashed with some other stuff to hide it or maybe there are other problems as well.
this pattern appears 4 times and looks like it is reducing the functions that are exposed to the 'whitelist'. i presume the modules have dangerous functions in the prototype chain and clients were able to invoke them.
- return moduleExports[metadata.name];
+ if (hasOwnProperty.call(moduleExports, metadata.name)) {
+ return moduleExports[metadata.name];
+ }
+ return (undefined: any);
- hackhomelab 10mo agoIt could also be https://github.com/facebook/react/commit/7dc903cd29dac55efb4424853fd0442fef3a8700 https://github.com/facebook/react/commit/7dc903cd29dac55efb4... ("This also fixes a critical security vulnerability.")
- nine_k 10mo agoIt does the same thing here, too: https://github.com/facebook/react/commit/7dc903cd29dac55efb4424853fd0442fef3a8700#diff-26dd4970d5e3c8a592e7a3b7562553cb60ce7e7a1d06734c23ae647f8f59d4e6 https://github.com/facebook/react/commit/7dc903cd29dac55efb4...