HIGH7.7
GHSA-jxfh-8wgv-vfr2
Prototype pollution in dojo
Quick fix
GHSA-jxfh-8wgv-vfr2 — dojo: upgrade to the fixed version with the command below.
npm install dojo@1.11.10Details
In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution.
Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values.
This has been patched in versions 1.12.8, 1.13.7, 1.14.6, 1.15.3 and 1.16.2
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/dojo/dojo/security/advisories/GHSA-jxfh-8wgv-vfr2[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2020-5258[ADVISORY]
- https://github.com/dojo/dojo/commit/20a00afb68f5587946dc76fbeaa68c39bda2171d[WEB]
- https://github.com/dojo/dojo[PACKAGE]
- https://lists.apache.org/thread.html/r3638722360d7ae95f874280518b8d987d799a76df7a9cd78eac33a1b@%3Cusers.qpid.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/r665fcc152bd0fec9f71511a6c2435ff24d3a71386b01b1a6df326fd3@%3Cusers.qpid.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/rf481b3f25f05c52ba4e24991a941c1a6e88d281c6c9360a806554d00@%3Cusers.qpid.apache.org%3E[WEB]
- https://lists.debian.org/debian-lts-announce/2020/03/msg00012.html[WEB]
- https://www.oracle.com//security-alerts/cpujul2021.html[WEB]
- https://www.oracle.com/security-alerts/cpujan2022.html[WEB]
- https://www.oracle.com/security-alerts/cpujul2020.html[WEB]
- https://www.oracle.com/security-alerts/cpujul2022.html[WEB]
- https://www.oracle.com/security-alerts/cpuoct2021.html[WEB]