Low severity3.7NVD Advisory· Published Jun 15, 2020· Updated Jun 17, 2026
CVE-2020-4051
CVE-2020-4051
Description
In Dijit before versions 1.11.11, and greater than or equal to 1.12.0 and less than 1.12.9, and greater than or equal to 1.13.0 and less than 1.13.8, and greater than or equal to 1.14.0 and less than 1.14.7, and greater than or equal to 1.15.0 and less than 1.15.4, and greater than or equal to 1.16.0 and less than 1.16.3, there is a cross-site scripting vulnerability in the Editor's LinkDialog plugin. This has been fixed in 1.11.11, 1.12.9, 1.13.8, 1.14.7, 1.15.4, 1.16.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
dijitnpm | < 1.11.11 | 1.11.11 |
dijitnpm | >= 1.12.0, < 1.12.9 | 1.12.9 |
dijitnpm | >= 1.13.0, < 1.13.8 | 1.13.8 |
dijitnpm | >= 1.14.0, < 1.14.7 | 1.14.7 |
dijitnpm | >= 1.15.0, < 1.15.4 | 1.15.4 |
dijitnpm | >= 1.16.0, < 1.16.3 | 1.16.3 |
Affected products
9cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*+ 1 more
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
- cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:*
- Dojo/dijitv5Range: < 1.11.11
Patches
Vulnerability mechanics
References
8- github.com/dojo/dijit/commit/462bdcd60d0333315fe69ab4709c894d78f61301nvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpuoct2020.htmlnvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-cxjc-r2fp-7mq6ghsaADVISORY
- github.com/dojo/dijit/security/advisories/GHSA-cxjc-r2fp-7mq6nvdThird Party AdvisoryWEB
- lists.debian.org/debian-lts-announce/2023/01/msg00030.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-4051ghsaADVISORY
- security.netapp.com/advisory/ntap-20201023-0003/nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20201023-0003ghsaWEB
News mentions
0No linked articles in our index yet.