From 8f461072f576cdf72c088a952ef342281a7c44d6 Mon Sep 17 00:00:00 2001 From: Raymond Hill Date: Tue, 11 Jan 2022 11:06:11 -0500 Subject: [PATCH] Fix selfie with invalid data in some circumstances Reported internally. The issue involves `removeparam` filters with a regex value. When such filter was visited before a selfie was created, this would cause the created selfie to persist a RegExp object, which can't be serialized. This would cause exceptions to be thrown when uBO would be subsequently loaded with the tainted selfie, since uBO would try to execute a plain Object as a RegExp. --- src/js/static-net-filtering.js | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/src/js/static-net-filtering.js b/src/js/static-net-filtering.js index 8609f80e0..eaa09d38f 100644 --- a/src/js/static-net-filtering.js +++ b/src/js/static-net-filtering.js @@ -1645,7 +1645,7 @@ const FilterModifier = class { filterData[idata+2] = args[2]; // type filterData[idata+3] = filterRefAdd({ value: args[3], - cache: null, + $cache: null, }); return idata; } @@ -1694,11 +1694,11 @@ const FilterModifierResult = class { } get cache() { - return this.refs.cache; + return this.refs.$cache; } set cache(a) { - this.refs.cache = a; + this.refs.$cache = a; } logData() { @@ -3523,7 +3523,7 @@ FilterCompiler.prototype.FILTER_UNSUPPORTED = 2; const FilterContainer = function() { this.compilerVersion = '8'; - this.selfieVersion = '8'; + this.selfieVersion = '9'; this.MAX_TOKEN_LENGTH = MAX_TOKEN_LENGTH; this.optimizeTaskId = undefined;