CVE-2018-1000665
Description
Dojo Dojo Objective Harness (DOH) version prior to version 1.14 contains a Cross Site Scripting (XSS) vulnerability in unit.html and testsDOH/_base/loader/i18n-exhaustive/i18n-test/unit.html and testsDOH/_base/i18nExhaustive.js in the DOH that can result in Victim attacked through their browser - deliver malware, steal HTTP cookies, bypass CORS trust. This attack appear to be exploitable via Victims are typically lured to a web site under the attacker's control; the XSS vulnerability on the target domain is silently exploited without the victim's knowledge. This vulnerability appears to have been fixed in 1.14.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.dojotoolkit:dojoMaven | < 1.14 | 1.14 |
Affected products
2Patches
Vulnerability mechanics
References
4- dojotoolkit.org/blog/dojo-1-14-releasednvdPatchRelease NotesVendor AdvisoryWEB
- github.com/advisories/GHSA-vmq9-cm7m-4p8pghsaADVISORY
- github.com/dojo/dojo/pull/307nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2018-1000665ghsaADVISORY
News mentions
0No linked articles in our index yet.