Ban setting 'Object.prototype.__proto__' as Proxy to prevent circular referencing (#4961)

in prototype chain.

This patch fixes #4941

JerryScript-DCO-1.0-Signed-off-by: Martin Negyokru negyokru@inf.u-szeged.hu
This commit is contained in:
mnegyokru
2022-01-14 11:02:19 +01:00
committed by GitHub
parent e9da834385
commit 57547d1261
2 changed files with 36 additions and 0 deletions
@@ -3332,6 +3332,15 @@ ecma_op_ordinary_object_set_prototype_of (ecma_object_t *obj_p, /**< base object
#if JERRY_BUILTIN_PROXY
if (ECMA_OBJECT_IS_PROXY (iter_p))
{
/**
* Prevent setting 'Object.prototype.__proto__'
* to avoid circular referencing in the prototype chain.
*/
if (obj_p == ecma_builtin_get (ECMA_BUILTIN_ID_OBJECT_PROTOTYPE))
{
return ECMA_VALUE_FALSE;
}
break;
}
#endif /* JERRY_BUILTIN_PROXY */