Description
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.16.4
References
- GHSA-m8gw-hjpr-rjv7
- snyk.io
- www.oracle.com
- lists.debian.org
- CVE-2021-23450
- CWE-1321
- CAPEC-310
- OWASP 2021-A6
Related Issues
- npm package rfc6902 vulnerable to Prototype Pollution - CVE-2021-4245
- Prototype Pollution in sey - CVE-2021-23663
- Prototype Pollution in jointjs - CVE-2021-23444
- Prototype pollution in dojo - dojo - CVE-2020-5258
You might also like:
- Tags:
- npm
- dojo
Anything's wrong? Let us know Last updated on January 31, 2023


