Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian 10 DLA-3289-1 Critical: Dojo XSS and Pollution Issues

debian lts
Calendar Grey January 29, 2023
Dist Debian Esm H88
Update dojo libraries to address severe XSS vulnerabilities and prototype pollution concerns highlighted in Debian LTS Advisory DLA-3289-1.
Two vulnerabilities were found in dojo, a modular JavaScript toolkit, that could result in information disclosure

Summary

CVE-2020-4051

The Dijit Editor's LinkDialog plugin of dojo 1.14.0 to 1.14.7 is
vulnerable to cross-site scripting (XSS) attacks.

CVE-2021-23450

Prototype pollution vulnerability via the setObject() function.

For Debian 10 buster, these problems have been fixed in version
1.14.2+dfsg1-1+deb10u3.

We recommend that you upgrade your dojo packages.

For the detailed security status of dojo please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/dojo

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

Package: dojo
Version: 1.14.2+dfsg1-1+deb10u3
CVE ID: CVE-2020-4051 CVE-2021-23450
Debian Bug: 970000 1014785

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here