CVE-2020-5259
Prototype Pollution in Dojox
7.7
HIGH
CVSS 3.1
EPSS 0.28%
Description
In affected versions of dojox (NPM package), the jqMix method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values. This has been patched in versions 1.11.10, 1.12.8, 1.13.7, 1.14.6, 1.15.3 and 1.16.2
How to fix CVE-2020-5259
To remediate CVE-2020-5259, upgrade the affected package to a fixed version below.
- —upgrade to 1.15.3+dfsg1-1 or later
- —upgrade to 1.11.10 or later
Is CVE-2020-5259 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 1.15.3+dfsg1-1
- from 0, < 1.11.10
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.7 | CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N |