MEDIUM
GHSA-39cx-xcwj-3rc4
Cross-Site Scripting in dojo
Quick fix
GHSA-39cx-xcwj-3rc4 — dojo: upgrade to the fixed version with the command below.
npm install dojo@1.1.0Details
Affected versions of `dojo` are susceptible to a cross-site scripting vulnerability in the `dijit.Editor` and `textarea` components, which execute their contents as Javascript, even when sanitized.
## Recommendation
Update to version 1.1.0 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2008-6681[ADVISORY]
- https://bugs.dojotoolkit.org/ticket/2140[WEB]
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49883[WEB]
- https://www.npmjs.com/advisories/107[WEB]
- http://trac.dojotoolkit.org/changeset/15346[WEB]
- http://trac.dojotoolkit.org/ticket/2140[WEB]
- http://www.dojotoolkit.org/book/dojo-1-1-release-notes[WEB]
- http://www.securityfocus.com/bid/34661[WEB]