VDB
Sign up
MEDIUM

GHSA-39cx-xcwj-3rc4

Cross-Site Scripting in dojo

Quick fix

GHSA-39cx-xcwj-3rc4 — dojo: upgrade to the fixed version with the command below.

npm install dojo@1.1.0

Details

Affected versions of `dojo` are susceptible to a cross-site scripting vulnerability in the `dijit.Editor` and `textarea` components, which execute their contents as Javascript, even when sanitized.

## Recommendation

Update to version 1.1.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/dojo
Introduced in: 0Fixed in: 1.1.0
Fixnpm install dojo@1.1.0

References