CVE-2021-23450

Description

All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
2.411

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are affected in Oracle WebLogic Server 12.2.1.4.0Windows
Multiple vulnerabilities are affected in Oracle WebLogic Server 14.1.1.0.0Windows
Multiple Vulnerabilities are affected in IBM TXSeries for Multiplatforms 9.1Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 20.0.0.2Windows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.3.0Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 19.0.0.3Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 21.0.3.1Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 22.0.2Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.2.1Windows
Multiple Vulnerabilities are affected in IBM TXSeries for Multiplatforms 8.2Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 23.0.2Windows
Modular JavaScript library (USN-7569-1) libjs-dojo-core_1.15.4+dfsg1-1ubuntu0.1_all.debLinux
Modular JavaScript library (USN-7569-1) libjs-dojo-dijit_1.15.4+dfsg1-1ubuntu0.1_all.debLinux
Modular JavaScript library (USN-7569-1) libjs-dojo-dojox_1.15.4+dfsg1-1ubuntu0.1_all.debLinux
Modular JavaScript library (USN-7569-1) shrinksafe_1.15.4+dfsg1-1ubuntu0.1_all.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234