UBUNTU-CVE-2020-4051
Dashboard / Vulnerabilities / UBUNTU-CVE-2020-4051
UBUNTU-CVE-2020-4051
Summary:
Details: In Dijit before versions 1.11.11, and greater than or equal to 1.12.0 and less than 1.12.9, and greater than or equal to 1.13.0 and less than 1.13.8, and greater than or equal to 1.14.0 and less than 1.14.7, and greater than or equal to 1.15.0 and less than 1.15.4, and greater than or equal to 1.16.0 and less than 1.16.3, there is a cross-site scripting vulnerability in the Editor's LinkDialog plugin. This has been fixed in 1.11.11, 1.12.9, 1.13.8, 1.14.7, 1.15.4, 1.16.3.
References: https://ubuntu.com/security/CVE-2020-4051, https://github.com/dojo/dijit/commit/462bdcd60d0333315fe69ab4709c894d78f61301, https://github.com/dojo/dijit/security/advisories/GHSA-cxjc-r2fp-7mq6, https://www.cve.org/CVERecord?id=CVE-2020-4051, https://ubuntu.com/security/notices/USN-7569-1
Affected packages
Package
Name: dojo
Purl: pkg:deb/ubuntu/[email protected]+dfsg-2ubuntu0.1~esm1?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
