VYPR

Dojo

by Linux Foundation

CVEs (2)

  • CVE-2021-23450HigDec 17, 2021
    risk 0.51cvss 7.5epss 0.30

    All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.

  • CVE-2020-5258HigMar 10, 2020
    risk 0.43cvss 7.7epss 0.04

    In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes…