Dojo
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-23450 | Hig | 0.51 | 7.5 | 0.30 | Dec 17, 2021 | All versions of package dojo are vulnerable to Prototype Pollution via the setObject function. | ||
| CVE-2020-5258 | Hig | 0.43 | 7.7 | 0.04 | Mar 10, 2020 | In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes… |
- risk 0.51cvss 7.5epss 0.30
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
- risk 0.43cvss 7.7epss 0.04
In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes…