Опубликовано: 17 дек. 2021
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 7.5
Описание
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support, was needs-triage |
| devel | not-affected | 1.17.3+dfsg1-1 |
| esm-apps/bionic | needed | |
| esm-apps/focal | released | 1.15.0+dfsg1-1ubuntu0.1~esm1 |
| esm-apps/jammy | released | 1.15.4+dfsg1-1ubuntu0.1 |
| esm-apps/noble | not-affected | 1.17.2+dfsg1-2.1 |
| esm-apps/xenial | released | 1.10.4+dfsg-2ubuntu0.1~esm1 |
| focal | ignored | end of standard support, was needs-triage |
| hirsute | ignored | end of life |
| impish | ignored | end of life |
Показывать по
10
Ссылки на источники
EPSS
Процентиль: 85%
0.02411
Низкий
7.5 High
CVSS2
7.5 High
CVSS3
Связанные уязвимости
CVSS3: 7.5
redhat
около 4 лет назад
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
CVSS3: 7.5
nvd
около 4 лет назад
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
CVSS3: 7.5
debian
около 4 лет назад
All versions of package dojo are vulnerable to Prototype Pollution via ...
CVSS3: 9.8
fstec
около 4 лет назад
Уязвимость функции setObject библиотеки dojo, позволяющая нарушителю выполнить произвольный код
EPSS
Процентиль: 85%
0.02411
Низкий
7.5 High
CVSS2
7.5 High
CVSS3