CVE-2020-5258
In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values. This has been patched in versions 1.12.8, 1.13.7, 1.14.6, 1.15.3 and 1.16.2
- Affected products
- Alt Linux, Oracle Weblogic Server, Dojo
- Linuxfoundation Dojo
- < 1.11.10, 1.12.8, 1.13.7, 1.14.6, 1.15.3, 1.16.2
- Fix
- Available
- CVSS 3.1
- 7.7 HIGH
- EPSS
- 4.0% (89th percentile)
- Weakness
- CWE-94, CWE-1321
- NVD status
- Modified
- Published
- 2020-03-10
CVE-2020-5258 at NVD
No indexed exploits for CVE-2020-5258 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2020-5258 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.