Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-4051

Опубликовано: 13 июн. 2020
Источник: redhat
CVSS3: 4.8

Описание

In Dijit before versions 1.11.11, and greater than or equal to 1.12.0 and less than 1.12.9, and greater than or equal to 1.13.0 and less than 1.13.8, and greater than or equal to 1.14.0 and less than 1.14.7, and greater than or equal to 1.15.0 and less than 1.15.4, and greater than or equal to 1.16.0 and less than 1.16.3, there is a cross-site scripting vulnerability in the Editor's LinkDialog plugin. This has been fixed in 1.11.11, 1.12.9, 1.13.8, 1.14.7, 1.15.4, 1.16.3.

A flaw was found in dijit. A cross-site scripting vulnerability was identified in the Editor's LinkDialog plugin. The highest threat from this vulnerability is to data confidentiality and integrity.

Отчет

ipa as shipped with Red Hat Enterprise Linux 5, 6, 7, and 8 is not affected by this flaw because it does not use the dijit functionality of dojo.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ipaNot affected
Red Hat Enterprise Linux 7ipaNot affected
Red Hat Enterprise Linux 8idm:client/ipaNot affected
Red Hat Enterprise Linux 8idm:DL1/ipaNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1879724dojo: Cross-site scripting vulnerability in the editor's LinkDialog plugin

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
больше 5 лет назад

In Dijit before versions 1.11.11, and greater than or equal to 1.12.0 and less than 1.12.9, and greater than or equal to 1.13.0 and less than 1.13.8, and greater than or equal to 1.14.0 and less than 1.14.7, and greater than or equal to 1.15.0 and less than 1.15.4, and greater than or equal to 1.16.0 and less than 1.16.3, there is a cross-site scripting vulnerability in the Editor's LinkDialog plugin. This has been fixed in 1.11.11, 1.12.9, 1.13.8, 1.14.7, 1.15.4, 1.16.3.

CVSS3: 3.7
nvd
больше 5 лет назад

In Dijit before versions 1.11.11, and greater than or equal to 1.12.0 and less than 1.12.9, and greater than or equal to 1.13.0 and less than 1.13.8, and greater than or equal to 1.14.0 and less than 1.14.7, and greater than or equal to 1.15.0 and less than 1.15.4, and greater than or equal to 1.16.0 and less than 1.16.3, there is a cross-site scripting vulnerability in the Editor's LinkDialog plugin. This has been fixed in 1.11.11, 1.12.9, 1.13.8, 1.14.7, 1.15.4, 1.16.3.

CVSS3: 3.7
debian
больше 5 лет назад

In Dijit before versions 1.11.11, and greater than or equal to 1.12.0 ...

CVSS3: 3.7
github
больше 5 лет назад

Cross-site Scripting in dijit editor's LinkDialog plugin

CVSS3: 4.4
fstec
больше 5 лет назад

Уязвимость плагина LinkDialog модульной библиотеки для упрощения разработки основанных на JavaScript или AJAX приложений и сайтов Dojo Toolkit, позволяющая нарушителю оказать воздействие на целостность данных

4.8 Medium

CVSS3