High severity7.5NVD Advisory· Published Dec 17, 2021· Updated Jun 17, 2026
CVE-2021-23450
CVE-2021-23450
Description
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
dojonpm | <= 1.16.4 | — |
Affected products
12- cpe:2.3:a:oracle:communications_policy_management:12.6.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*range: >=17.7,<=17.12
- cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:primavera_unifier:20.12:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:primavera_unifier:21.12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
- dojo/dojodescription
Patches
Vulnerability mechanics
References
11- www.oracle.com/security-alerts/cpuapr2022.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpujul2022.htmlnvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-2313036nvdExploitMitigationThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-2313035nvdExploitMitigationThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBDOJO-2313034nvdExploitMitigationThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2313033nvdExploitMitigationThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-DOJO-1535223nvdExploitMitigationThird Party AdvisoryWEB
- github.com/advisories/GHSA-m8gw-hjpr-rjv7ghsaADVISORY
- github.com/dojo/dojo/blob/4c39c14349408fc8274e19b399ffc660512ed07c/_base/lang.js%23L172nvdBroken LinkThird Party AdvisoryWEB
- lists.debian.org/debian-lts-announce/2023/01/msg00030.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-23450ghsaADVISORY
News mentions
0No linked articles in our index yet.