Releases: medialize/URI.js
Releases · medialize/URI.js
1.19.11 (April 3rd 2022)
- SECURITY fixing
URI.parse()
handle excessive slashes in scheme-relative URLs - disclosed by zeyu2001 via https://huntr.dev/ - SECURITY fixing
URI.parse()
remove\r
(CR),\n
, (LF)\t
(TAB) - disclosed by haxatron via https://huntr.dev/
1.19.10 (March 5th 2022)
- SECURITY fixing
URI.parse()
handle excessive colons in protocol delimiter - disclosed by huydoppa via https://huntr.dev/
1.19.9 (March 3rd 2022)
- SECURITY fixing
URI.parse()
handle leading whitespace - disclosed by p0cas via https://huntr.dev/
1.19.8 (February 15th 2022)
- SECURITY fixing
URI.parse()
treat scheme case-insenstivie when handling excessive slackes and backslashes - PR #412 by r0hanSH
1.19.7 (July 14th 2021)
- SECURITY fixing
URI.parseQuery()
to prevent overwriting__proto__
in parseQuery() - disclosed privately by @NewEraCracker - SECURITY fixing
URI.parse()
to handle variable amounts of\
and/
in scheme delimiter as Node and Browsers do - disclosed privately by ready-research via https://huntr.dev/ - removed obsolete build tools
- updated jQuery versions (verifying compatibility with 1.12.4, 2.2.4, 3.6.0)
1.19.6 (February 13th 2021)
- SECURITY fixing
URI.parse()
to rewrite\
in scheme delimiter to/
as Node and Browsers do - disclosed privately by Yaniv Nizry from the CxSCA AppSec team at Checkmarx
1.19.5 (December 30th 2020)
- dropping jquery.URI.js from minified bundle accidentally added since v1.19.3 - Issue #404
1.19.4 (December 23rd 2020)
- SECURITY fixing
URI.parseAuthority()
to rewrite\
to/
as Node and Browsers do - followed up to by alesandroortiz in PR #403, relates to Issue #233
1.19.3 (December 20th 2020)
- SECURITY fixing
URI.parseAuthority()
to rewrite\
to/
as Node and Browsers do - disclosed privately by alesandroortiz, relates to Issue #233
1.19.2 (October 20th 2019)
- fixing
URI.build()
to properly handle relative paths when a scheme is given - Issue #387 - fixing
URI.buildQuery()
to properly handle empty param name - Issue #243, PR #383 - support Composer PR #386