VDB
Sign up
HIGH7.7

GHSA-jxfh-8wgv-vfr2

Prototype pollution in dojo

Quick fix

GHSA-jxfh-8wgv-vfr2 — dojo: upgrade to the fixed version with the command below.

npm install dojo@1.11.10

Details

In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution.

Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values.

This has been patched in versions 1.12.8, 1.13.7, 1.14.6, 1.15.3 and 1.16.2

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/dojo
Introduced in: 0Fixed in: 1.11.10
Fixnpm install dojo@1.11.10
npm/dojo
Introduced in: 1.12.0Fixed in: 1.12.8
Fixnpm install dojo@1.12.8
npm/dojo
Introduced in: 1.13.0Fixed in: 1.13.7
Fixnpm install dojo@1.13.7
npm/dojo
Introduced in: 1.14.0Fixed in: 1.14.6
Fixnpm install dojo@1.14.6
npm/dojo
Introduced in: 1.15.0Fixed in: 1.15.3
Fixnpm install dojo@1.15.3
npm/dojo
Introduced in: 1.16.0Fixed in: 1.16.2
Fixnpm install dojo@1.16.2

References