Description
The Dojox jQuery wrapper jqMix mixin method is vulnerable to Prototype Pollution.
Recommendation
Update the dojox package to the latest compatible version. Followings are version details:
Affected version(s): **>= 1.16.0, < 1.16.2 >= 1.15.0, < 1.15.3 >= 1.14.0, < 1.14.6 >= 1.13.0, < 1.13.7 >= 1.12.0, < 1.12.8 < 1.11.10** Patched version(s): **1.16.2 1.15.3 1.14.6 1.13.7 1.12.8 1.11.10**
References
Related Issues
- Prototype pollution in controlled-merge - CVE-2020-28268
- Prototype Pollution in gedi - CVE-2020-7727
- Prototype Pollution in tiny-conf - CVE-2020-7724
- Prototype Pollution in promisehelpers - CVE-2020-7723
You might also like:
- Tags:
- npm
- dojox
Anything's wrong? Let us know Last updated on January 09, 2023


