MGASA-2020-0232

Source
https://advisories.mageia.org/MGASA-2020-0232.html
Import Source
https://advisories.mageia.org/MGASA-2020-0232.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2020-0232
Related
Published
2020-05-27T09:52:46Z
Modified
2020-05-27T14:57:22Z
Summary
Updated dojo packages fix security vulnerability
Details

Updated dojo package fixes security vulnerabilities:

In affected versions of dojo, the deepCopy method is vulnerable to prototype Pollution. An attacker could manipulate these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values (CVE-2020-5258).

The Dojox jQuery wrapper jqMix mixin method is vulnerable to Prototype Pollution. An attacker could manipulate these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values (CVE-2020-5259).

References
Credits

Affected packages

Mageia:7 / dojo

Package

Name
dojo
Purl
pkg:rpm/mageia/dojo?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.14.6-1.mga7

Ecosystem specific

{
    "section": "core"
}