CRITICAL9.8
GHSA-84cm-x2q5-8225
dojox vulnerable to unescaped string injection
Quick fix
GHSA-84cm-x2q5-8225 — dojox: upgrade to the fixed version with the command below.
npm install dojox@1.14.0Details
In Dojo Toolkit before 1.14.0, there is unescaped string injection in dojox/Grid/DataGrid.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2018-15494[ADVISORY]
- https://github.com/dojo/dojox/pull/283[WEB]
- https://dojotoolkit.org/blog/dojo-1-14-released[WEB]
- https://github.com/advisories/GHSA-84cm-x2q5-8225[ADVISORY]
- https://github.com/dojo/dojox[PACKAGE]
- https://lists.debian.org/debian-lts-announce/2018/09/msg00002.html[WEB]