XSS possible for users of the Dijit Editor's LinkDialog plugin
Yes, 1.11.11, 1.12.9, 1.13.8, 1.14.7, 1.15.4, 1.16.3
Users may apply the patch made in these releases.
If you have any questions or comments about this advisory, open an issue in dojo/dijit
| Score | Percentile |
|---|---|
| 0.23% | 45.53% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 3.7 | 3.1 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-cxjc-r2fp-7mq6 ↗ |
| CVE | CVE-2020-4051 ↗ |
| CWE id | Name |
|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| npm | dijit | < 1.11.11 | 1.11.11 | — |
| npm | dijit | >= 1.12.0, < 1.12.9 | 1.12.9 | — |
| npm | dijit | >= 1.13.0, < 1.13.8 | 1.13.8 | — |
| npm | dijit | >= 1.14.0, < 1.14.7 | 1.14.7 | — |
| npm | dijit | >= 1.15.0, < 1.15.4 | 1.15.4 | — |
| npm | dijit | >= 1.16.0, < 1.16.3 | 1.16.3 | — |