CVE-2020-5258High· 7.7▾ TwilightIn affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects.…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.4 · likelihood 0.8 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
4.0%
In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values. This has been patched in versions 1.12.8, 1.13.7, 1.14.6, 1.15.3 and 1.16.2
dojo < 1.11.10dojo >= 1.12.0, < 1.12.8dojo >= 1.13.0, < 1.13.7dojo >= 1.14.0, < 1.14.6dojo >= 1.15.0, < 1.15.3dojo >= 1.16.0, < 1.16.2debian_linux = 8.0communications_application_session_controller = 3.9.0communications_policy_management = 12.5.0communications_pricing_design_center = 12.0.0.3.0documaker >= 12.6.0, <= 12.6.4mysql >= 7.3.0, <= 7.3.29mysql >= 7.4.0, <= 7.4.28mysql >= 7.5.0, <= 7.5.18mysql >= 7.6.0, <= 7.6.14mysql >= 8.0.0, <= 8.0.20primavera_unifier >= 17.7, <= 17.12primavera_unifier = 18.8primavera_unifier = 19.12primavera_unifier = 20.12webcenter_sites = 12.2.1.3.0webcenter_sites = 12.2.1.4.0weblogic_server = 12.2.1.4.0weblogic_server = 14.1.1.0.0Upgrade past the affected range:
dojo 1.16.2Connected by shared product, vendor, weakness, or advisory.
CVE-2021-23450High· 7.5All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
CVE-2021-23337High· 7.2Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
CVE-2018-1270Critical· 9.8Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging…
CVE-2021-29505High· 7.5XStream is software for serializing Java objects to XML and back again
CVE-2021-21345Medium· 5.8XStream is a Java library to serialize objects to XML and back again
CVE-2026-25153High· 7.7Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDocs