USN-7569-1
Dashboard / Vulnerabilities / USN-7569-1
USN-7569-1
Summary: dojo vulnerabilities
Details: It was discovered that Dojo did not correctly handle DataGrids. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-15494) It was discovered that Dojo was vulnerable to prototype pollution. An attacker could possibly use this issue to execute arbitrary code. (CVE-2021-23450) Jonathan Leitschuh discovered that Dojo did not correctly sanitize certain inputs. An attacker could possibly use this issue to execute a cross-site scripting (XSS) attack. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2019-10785, CVE-2020-4051)
References: https://ubuntu.com/security/notices/USN-7569-1, https://ubuntu.com/security/CVE-2018-15494, https://ubuntu.com/security/CVE-2019-10785, https://ubuntu.com/security/CVE-2020-4051, https://ubuntu.com/security/CVE-2021-23450
Affected packages
Package
Name: dojo
Purl: pkg:deb/ubuntu/dojo?arch=source&distro=esm-apps%2Fxenial
Affected ranges
Type: ECOSYSTEM
Events:
