Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cxjc-r2fp-7mq6

Опубликовано: 15 июн. 2020
Источник: github
Github: Прошло ревью
CVSS3: 3.7

Описание

Cross-site Scripting in dijit editor's LinkDialog plugin

Impact

XSS possible for users of the Dijit Editor's LinkDialog plugin

Patches

Yes, 1.11.11, 1.12.9, 1.13.8, 1.14.7, 1.15.4, 1.16.3

Workarounds

Users may apply the patch made in these releases.

For more information

If you have any questions or comments about this advisory, open an issue in dojo/dijit

Пакеты

Наименование

dijit

npm
Затронутые версииВерсия исправления

< 1.11.11

1.11.11

Наименование

dijit

npm
Затронутые версииВерсия исправления

>= 1.12.0, < 1.12.9

1.12.9

Наименование

dijit

npm
Затронутые версииВерсия исправления

>= 1.13.0, < 1.13.8

1.13.8

Наименование

dijit

npm
Затронутые версииВерсия исправления

>= 1.14.0, < 1.14.7

1.14.7

Наименование

dijit

npm
Затронутые версииВерсия исправления

>= 1.15.0, < 1.15.4

1.15.4

Наименование

dijit

npm
Затронутые версииВерсия исправления

>= 1.16.0, < 1.16.3

1.16.3

EPSS

Процентиль: 44%
0.00216
Низкий

3.7 Low

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 3.7
ubuntu
больше 5 лет назад

In Dijit before versions 1.11.11, and greater than or equal to 1.12.0 and less than 1.12.9, and greater than or equal to 1.13.0 and less than 1.13.8, and greater than or equal to 1.14.0 and less than 1.14.7, and greater than or equal to 1.15.0 and less than 1.15.4, and greater than or equal to 1.16.0 and less than 1.16.3, there is a cross-site scripting vulnerability in the Editor's LinkDialog plugin. This has been fixed in 1.11.11, 1.12.9, 1.13.8, 1.14.7, 1.15.4, 1.16.3.

CVSS3: 4.8
redhat
больше 5 лет назад

In Dijit before versions 1.11.11, and greater than or equal to 1.12.0 and less than 1.12.9, and greater than or equal to 1.13.0 and less than 1.13.8, and greater than or equal to 1.14.0 and less than 1.14.7, and greater than or equal to 1.15.0 and less than 1.15.4, and greater than or equal to 1.16.0 and less than 1.16.3, there is a cross-site scripting vulnerability in the Editor's LinkDialog plugin. This has been fixed in 1.11.11, 1.12.9, 1.13.8, 1.14.7, 1.15.4, 1.16.3.

CVSS3: 3.7
nvd
больше 5 лет назад

In Dijit before versions 1.11.11, and greater than or equal to 1.12.0 and less than 1.12.9, and greater than or equal to 1.13.0 and less than 1.13.8, and greater than or equal to 1.14.0 and less than 1.14.7, and greater than or equal to 1.15.0 and less than 1.15.4, and greater than or equal to 1.16.0 and less than 1.16.3, there is a cross-site scripting vulnerability in the Editor's LinkDialog plugin. This has been fixed in 1.11.11, 1.12.9, 1.13.8, 1.14.7, 1.15.4, 1.16.3.

CVSS3: 3.7
debian
больше 5 лет назад

In Dijit before versions 1.11.11, and greater than or equal to 1.12.0 ...

CVSS3: 4.4
fstec
больше 5 лет назад

Уязвимость плагина LinkDialog модульной библиотеки для упрощения разработки основанных на JavaScript или AJAX приложений и сайтов Dojo Toolkit, позволяющая нарушителю оказать воздействие на целостность данных

EPSS

Процентиль: 44%
0.00216
Низкий

3.7 Low

CVSS3

Дефекты

CWE-79