PT-2020-5622 · Dojo · Dojox

Dylans

·

Published

2020-03-10

·

Updated

2020-05-27

·

CVE-2020-5259

CVSS v3.1

7.7

High

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions dojox versions prior to 1.11.10 dojox versions prior to 1.12.8 dojox versions prior to 1.13.7 dojox versions prior to 1.14.6 dojox versions prior to 1.15.3 dojox versions prior to 1.16.2
Description The issue concerns the jqMix method in the dojox library, which is vulnerable to Prototype Pollution. This refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker can manipulate these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values.
Recommendations For dojox versions prior to 1.11.10, update to version 1.11.10 or later. For dojox versions prior to 1.12.8, update to version 1.12.8 or later. For dojox versions prior to 1.13.7, update to version 1.13.7 or later. For dojox versions prior to 1.14.6, update to version 1.14.6 or later. For dojox versions prior to 1.15.3, update to version 1.15.3 or later. For dojox versions prior to 1.16.2, update to version 1.16.2 or later. As a temporary workaround, consider disabling the jqMix method until a patch is available.

Exploit

Fix

Code Injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01322
CVE-2020-5259
DLA-2139-1
GHSA-3HW5-Q855-G6CW
MGASA-2020-0232

Affected Products

Dojox