VDB
Sign up
MEDIUM

GHSA-536q-8gxx-m782

Cross-Site Scripting in dojo

Quick fix

GHSA-536q-8gxx-m782 — dojo: upgrade to the fixed version with the command below.

npm install dojo@1.13.1

Details

Versions of `dojo` prior to 1.4.2 are vulnerable to DOM-based Cross-Site Scripting (XSS). The package does not sanitize URL parameters in the `_testCommon.js` and `runner.html` test files, allowing attackers to execute arbitrary JavaScript in the victim's browser.

## Recommendation

Upgrade to version 1.4.2 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/dojo
Introduced in: 1.13.0Fixed in: 1.13.1
Fixnpm install dojo@1.13.1
npm/dojo
Introduced in: 1.12.0Fixed in: 1.12.4
Fixnpm install dojo@1.12.4
npm/dojo
Introduced in: 1.11.0Fixed in: 1.11.6
Fixnpm install dojo@1.11.6
npm/dojo
Introduced in: 1.10.0Fixed in: 1.10.10
Fixnpm install dojo@1.10.10

References