← back
CVE-2020-5259

Prototype Pollution in Dojox

CVSS 7.7 HIGHEPSS 2.0%CWE-94
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.7EPSS 2.0%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
10 Mar 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In affected versions of dojox (NPM package), the jqMix method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values. This has been patched in versions 1.11.10, 1.12.8, 1.13.7, 1.14.6, 1.15.3 and 1.16.2
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Affected products
dojo · dojox

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →