pagekit / vue-resource

The HTTP client for Vue.js
MIT License
10.08k stars 1.6k forks source link

Security fix for ReDoS #759

Open ready-research opened 2 years ago

ready-research commented 2 years ago

Security fix for ReDoS vulnerability.

https://developer.mozilla.org/docs/Web/JavaScript/Reference/Global_Objects/String/Trim

Reported in https://www.huntr.dev/bounties/7e6cbdf3-e360-47a1-aca3-24b5e4eea9b7

Before Applying patch result: time_cost: 2639

After applying the patch result: time_cost: 4