Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-5259

Опубликовано: 10 мар. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5
CVSS3: 7.7

Описание

In affected versions of dojox (NPM package), the jqMix method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values. This has been patched in versions 1.11.10, 1.12.8, 1.13.7, 1.14.6, 1.15.3 and 1.16.2

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

1.15.3+dfsg1-1
eoan

ignored

end of life
esm-apps-legacy/xenial

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

not-affected

1.15.3+dfsg1-1
esm-apps/noble

not-affected

1.15.3+dfsg1-1
esm-apps/resolute

not-affected

1.15.3+dfsg1-1
esm-apps/xenial

ignored

end of ESM support, was needs-triage

Показывать по

EPSS

Процентиль: 79%
0.02001
Низкий

5 Medium

CVSS2

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 7.7
nvd
больше 6 лет назад

In affected versions of dojox (NPM package), the jqMix method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values. This has been patched in versions 1.11.10, 1.12.8, 1.13.7, 1.14.6, 1.15.3 and 1.16.2

CVSS3: 7.7
debian
больше 6 лет назад

In affected versions of dojox (NPM package), the jqMix method is vulne ...

CVSS3: 7.7
github
больше 6 лет назад

Prototype Pollution in Dojox

CVSS3: 5.3
fstec
больше 6 лет назад

Уязвимость реализации метода jqMix библиотеки dojox (пакет NPM), позволяющая нарушителю оказать воздействие на целостность данных

EPSS

Процентиль: 79%
0.02001
Низкий

5 Medium

CVSS2

7.7 High

CVSS3