dojo vulnerabilities
CVEs whose affected-version data names the dojo package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2021-23450High· 7.5All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
▾ Twilightlinuxfoundation · dojoEPSS 30%via NVD
CVE-2020-5258High· 7.7In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution
In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects.…
▾ Twilightlinuxfoundation · dojoEPSS 4.0%via NVD