Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 498
Alerts This Week
Warning Icon 1 498

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
172

Ubuntu 22.04 LTS USN-7569-1 critical: Dojo security issues

Several security issues were fixed in Dojo.. ========================================================================== Ubuntu Security Notice USN-7569-1 June 16, 2025 dojo vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Dojo. Software Description: - dojo: Modular JavaScript library Details: It was discovered that Dojo did not correctly handle DataGrids. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-15494) It was discovered that Dojo was vulnerable to prototype pollution. An attacker could possibly use this issue to execute arbitrary code. (CVE-2021-23450) Jonathan Leitschuh discovered that Dojo did not correctly sanitize certain inputs. An attacker could possibly use this issue to execute a cross-site scripting (XSS) attack. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2019-10785, CVE-2020-4051) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS libjs-dojo-core 1.15.4+dfsg1-1ubuntu0.1 libjs-dojo-dijit 1.15.4+dfsg1-1ubuntu0.1 libjs-dojo-dojox 1.15.4+dfsg1-1ubuntu0.1 shrinksafe 1.15.4+dfsg1-1ubuntu0.1 Ubuntu 20.04 LTS libjs-dojo-core 1.15.0+dfsg1-1ubuntu0.1~esm1 Available with Ubuntu Pro libjs-dojo-dijit 1.15.0+dfsg1-1ubuntu0.1~esm1 Available with Ubuntu Pro libjs-dojo-dojox 1.15.0+dfsg1-1ubuntu0.1~esm1 Available with Ubuntu Pro shrinksafe 1.15.0+dfsg1-1ubuntu0.1~esm1 Available with UbuntuPro Ubuntu 16.04 LTS libjs-dojo-core 1.10.4+dfsg-2ubuntu0.1~esm1 Available with Ubuntu Pro libjs-dojo-dijit 1.10.4+dfsg-2ubuntu0.1~esm1 Available with Ubuntu Pro libjs-dojo-dojox 1.10.4+dfsg-2ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7569-1 CVE-2018-15494, CVE-2019-10785, CVE-2020-4051, CVE-2021-23450 Package Information: https://launchpad.net/ubuntu/+source/dojo/1.15.4+dfsg1-1ubuntu0.1 . Explore the recent Ubuntu USN-7569-1 release that tackles vulnerabilities in Dojo and offers essential patches for enhanced security measures.. Ubuntu security, Dojo vulnerabilities, software update, code execution, XSS fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 16, 2025 Critical Ubuntu
203

Mageia 8: MGASA-2023-0039 Critical Dojo XSS And Prototype Threats

Dijit Editor's LinkDialog plugin of dojo 1.14.0 to 1.14.7 is vulnerable to cross-site scripting (XSS) attacks. (CVE-2020-4051) Prototype pollution vulnerability via the setObject() function. (CVE-2021-23450) . MGASA-2023-0039 - Updated dojo packages fix security vulnerability Publication date: 07 Feb 2023 URL: https://advisories.mageia.org/MGASA-2023-0039.html Type: security Affected Mageia releases: 8 CVE: CVE-2020-4051, CVE-2021-23450 Dijit Editor's LinkDialog plugin of dojo 1.14.0 to 1.14.7 is vulnerable to cross-site scripting (XSS) attacks. (CVE-2020-4051) Prototype pollution vulnerability via the setObject() function. (CVE-2021-23450) References: - https://bugs.mageia.org/show_bug.cgi?id=31491 - https://github.com/dojo/dijit/security/advisories/GHSA-cxjc-r2fp-7mq6 - https://github.com/advisories/GHSA-m8gw-hjpr-rjv7 - https://www.cve.org/CVERecord?id=CVE-2020-4051 - https://www.cve.org/CVERecord?id=CVE-2021-23450 SRPMS: - 8/core/dojo-1.16.5-1.mga8 . Mageia 2023-0040 warns users about vulnerabilities in the CMS plugin regarding XSS attacks and prototype tampering threats. Keep informed on the patch details.. dojo Security, XSS Prevention, Mageia Advisory, Web Security, Software Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 07, 2023 Critical Mageia
197

Debian 10 DLA-3289-1 Critical: Dojo XSS and Pollution Issues

Two vulnerabilities were found in dojo, a modular JavaScript toolkit, that could result in information disclosure. CVE-2020-4051 . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3289-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Guilhem Moulin January 28, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : dojo Version : 1.14.2+dfsg1-1+deb10u3 CVE ID : CVE-2020-4051 CVE-2021-23450 Debian Bug : 970000 1014785 Two vulnerabilities were found in dojo, a modular JavaScript toolkit, that could result in information disclosure. CVE-2020-4051 The Dijit Editor's LinkDialog plugin of dojo 1.14.0 to 1.14.7 is vulnerable to cross-site scripting (XSS) attacks. CVE-2021-23450 Prototype pollution vulnerability via the setObject() function. For Debian 10 buster, these problems have been fixed in version 1.14.2+dfsg1-1+deb10u3. We recommend that you upgrade your dojo packages. For the detailed security status of dojo please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/dojo Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Update dojo libraries to address severe XSS vulnerabilities and prototype pollution concerns highlighted in Debian LTS Advisory DLA-3289-1.. Debian Security, Dojo Update, JavaScript Toolkit. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 29, 2023 Critical Debian LTS
203

Mageia: 2020-0126 Moderate: Dojo Cross-Site Scripting Threat

Updated dojo package fixes security vulnerability: dojox was vulnerable to Cross-site Scripting. This was due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them (CVE-2019-10785). . MGASA-2020-0126 - Updated dojo packages fix security vulnerability Publication date: 06 Mar 2020 URL: https://advisories.mageia.org/MGASA-2020-0126.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-10785 Updated dojo package fixes security vulnerability: dojox was vulnerable to Cross-site Scripting. This was due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them (CVE-2019-10785). References: - https://bugs.mageia.org/show_bug.cgi?id=26287 - https://lists.debian.org/debian-lts-announce/2020/02/msg00033.html - https://www.cve.org/CVERecord?id=CVE-2019-10785 SRPMS: - 7/core/dojo-1.14.5-1.mga7 . Fedora 2021-0312 updates nano software to address Denial of Service vulnerability. Release date: 15 Apr 2021.. Dojo Security Update, Mageia Advisory, Cross-Site Scripting, Security Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 06, 2020 Important Mageia
197

Debian 8: DLA-1492-1 Critical: Dojo String Injection Issue Fix

It was discovered that there was a string injection vulnerability in the "dojo" Javascript library. For Debian 8 "Jessie", this issue has been fixed in dojo version . Package : dojo Version : 1.10.2+dfsg-1+deb8u1 CVE ID : CVE-2018-15494 Debian Bug : #906540 It was discovered that there was a string injection vulnerability in the "dojo" Javascript library. For Debian 8 "Jessie", this issue has been fixed in dojo version 1.10.2+dfsg-1+deb8u1 by Abhijith PA. We recommend that you upgrade your dojo packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'` This email address is being protected from spambots. You need JavaScript enabled to view it. / chris-lamb.co.uk `- . Patch dojo library to rectify string injection vulnerability for Debian 8 systems. Fortify security measures through this essential upgrade.. dojo Security Fix, Debian Update, Injection Threat, Software Patch, Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 03, 2018 Critical Debian LTS
89

Fedora Kdelibs3 Important DoS Code Execution Fix 2009-8046

This update fixes several security issues in the KDE 3 compatibility version of KHTML (CVE-2009-1725, CVE-2009-1690, CVE-2009-1687, CVE-2009-1698, CVE-2009-2537) which may lead to a denial of service or potentially even arbitrary code execution. In addition, the package was fixed to build with the latest version of automake.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-8046 2009-07-27 21:07:28 -------------------------------------------------------------------------------- Name : kdelibs3 Product : Fedora 11 Version : 3.5.10 Release : 13.fc11 URL : https://kde.org/ Summary : K Desktop Environment 3 - Libraries Description : Libraries for the K Desktop Environment 3: KDE Libraries included: kdecore (KDE core library), kdeui (user interface), kfm (file manager), khtmlw (HTML widget), kio (Input/Output, networking), kspell (spelling checker), jscript (javascript), kab (addressbook), kimgio (image manipulation). -------------------------------------------------------------------------------- Update Information: This update fixes several security issues in the KDE 3 compatibility version of KHTML (CVE-2009-1725, CVE-2009-1690, CVE-2009-1687, CVE-2009-1698, CVE-2009-2537) which may lead to a denial of service or potentially even arbitrary code execution. In addition, the package was fixed to build with the latest version of automake. -------------------------------------------------------------------------------- ChangeLog: * Sun Jul 26 2009 Kevin Kofler - 3.5.10-13 - fix CVE-2009-2537 - select length DoS - fix CVE-2009-1725 - crash, possible ACE in numeric character references - fix CVE-2009-1690 - crash, possible ACE in KHTML ( . Addresses major vulnerabilities in KDE kdelibs3 for Fedora 11, mitigating potential DoS attacks and the risk of code execution. Ensure you update promptly for enhanced security.. KDE Libraries,Fedora Update,kdelibs3,security patch,code execution threat. .Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 28, 2009 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200