CVE-2020-5258
dojo - security update
7.7
HIGH
CVSS 3.1
EPSS 1.5%
Description
In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values. This has been patched in versions 1.12.8, 1.13.7, 1.14.6, 1.15.3 and 1.16.2
How to fix CVE-2020-5258
To remediate CVE-2020-5258, upgrade the affected package to a fixed version below.
- —upgrade to 1.15.3+dfsg1-1 or later
- —upgrade to 1.10.2+dfsg-1+deb8u3 or later
- —upgrade to 1.11.10 or later
Is CVE-2020-5258 being exploited?
Low — EPSS is 1.5%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 1.15.3+dfsg1-1
- from 0, < 1.10.2+dfsg-1+deb8u3
- from 0, < 1.11.10
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.7 | CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N |