Skip to content

Commit 42c00e7

Browse files
committed
3.1.4 release with security fixes
1 parent c65c9b2 commit 42c00e7

File tree

8 files changed

+12
-11
lines changed

8 files changed

+12
-11
lines changed

SECURITY.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
Tiny values the work of security researchers in improving the security of technology products worldwide. We welcome researchers who wish to responsibly disclose vulnerabilities in our products or systems. Note that we do not offer any “bug bounty” program or any form of payment for disclosed vulnerabilities. If you would like to report a vulnerability, please email infosec@tiny.cloud.

js/jquery.plupload.queue/jquery.plupload.queue.js

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -301,7 +301,7 @@ used as it is.
301301

302302
// Rename file and glue extension back on
303303
file.name = targetInput.val() + ext;
304-
targetSpan.html(file.name);
304+
targetSpan.text(file.name);
305305
targetInput.blur();
306306
}
307307
});

js/jquery.plupload.queue/jquery.plupload.queue.min.js

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

js/jquery.ui.plupload/jquery.ui.plupload.js

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -489,7 +489,7 @@ $.widget("ui.plupload", {
489489
break;
490490
}
491491

492-
message += " <br /><i>" + details + "</i>";
492+
message += " <br /><i>" + plupload.xmlEncode(details) + "</i>";
493493

494494
self._trigger('error', null, { up: up, error: err } );
495495

@@ -1305,7 +1305,7 @@ $.widget("ui.plupload", {
13051305
// Rename file and glue extension back on
13061306
if (e.keyCode === 13) {
13071307
file.name = nameInput.val() + ext;
1308-
nameSpan.html(file.name);
1308+
nameSpan.text(file.name);
13091309
}
13101310
nameInput.blur();
13111311
}

js/jquery.ui.plupload/jquery.ui.plupload.min.js

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

package.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
{
22
"name": "plupload",
33
"description": "Plupload is a JavaScript API for dealing with file uploads it supports features like multiple file selection, file type filtering, request chunking, client side image scaling and it uses different runtimes to achieve this such as HTML 5, Silverlight and Flash.",
4-
"version": "3.1.3",
5-
"releaseDate": "2021-03-29",
4+
"version": "3.1.4",
5+
"releaseDate": "2021-11-15",
66
"author": "Ephox",
77
"contributors": [{
88
"name": "Davit Barbakadze",

src/jquery.plupload.queue/jquery.plupload.queue.js

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -223,7 +223,7 @@ used as it is.
223223

224224
fileList.append(
225225
'<li id="' + file.id + '">' +
226-
'<div class="plupload_file_name"><span>' + file.name + '</span></div>' +
226+
'<div class="plupload_file_name"><span>' + plupload.xmlEncode(file.name) + '</span></div>' +
227227
'<div class="plupload_file_action"><a href="#"></a></div>' +
228228
'<div class="plupload_file_status">' + file.percent + '%</div>' +
229229
'<div class="plupload_file_size">' + plupload.formatSize(file.size) + '</div>' +
@@ -301,7 +301,7 @@ used as it is.
301301

302302
// Rename file and glue extension back on
303303
file.name = targetInput.val() + ext;
304-
targetSpan.html(file.name);
304+
targetSpan.text(file.name);
305305
targetInput.blur();
306306
}
307307
});

src/jquery.ui.plupload/jquery.ui.plupload.js

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -489,7 +489,7 @@ $.widget("ui.plupload", {
489489
break;
490490
}
491491

492-
message += " <br /><i>" + details + "</i>";
492+
message += " <br /><i>" + plupload.xmlEncode(details) + "</i>";
493493

494494
self._trigger('error', null, { up: up, error: err } );
495495

@@ -1305,7 +1305,7 @@ $.widget("ui.plupload", {
13051305
// Rename file and glue extension back on
13061306
if (e.keyCode === 13) {
13071307
file.name = nameInput.val() + ext;
1308-
nameSpan.html(file.name);
1308+
nameSpan.text(file.name);
13091309
}
13101310
nameInput.blur();
13111311
}

0 commit comments

Comments
 (0)