cbcvebase.
CVE-2021-23450
published 2021-12-17

CVE-2021-23450: All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.

Affected

20 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandojo< dojo 1.17.2+dfsg1-1 (bookworm)dojo 1.17.2+dfsg1-1 (bookworm)
linuxfoundationdojo< unspecifiedunspecified
linuxfoundationdojo< 1.17.01.17.0
linuxfoundationdojo>= 0 < 1.15.4+dfsg1-1+deb11u11.15.4+dfsg1-1+deb11u1
linuxfoundationdojo>= 0 < 1.17.2+dfsg1-11.17.2+dfsg1-1
linuxfoundationdojo>= 0 < 1.17.2+dfsg1-11.17.2+dfsg1-1
linuxfoundationdojo>= 0 < 1.17.2+dfsg1-11.17.2+dfsg1-1
linuxfoundationdojo>= 0 < 1.15.4+dfsg1-1ubuntu0.11.15.4+dfsg1-1ubuntu0.1
linuxfoundationdojo>= 0 < 1.10.4+dfsg-2ubuntu0.1~esm11.10.4+dfsg-2ubuntu0.1~esm1
linuxfoundationdojo>= 0 < 1.15.0+dfsg1-1ubuntu0.1~esm11.15.0+dfsg1-1ubuntu0.1~esm1
linuxfoundationdojo0 – 1.16.4
oraclecommunications_policy_management
oracleprimavera_unifier
oracleprimavera_unifier
oracleprimavera_unifier
oracleprimavera_unifier
oracleprimavera_unifier17.7 – 17.12
oracleweblogic_server
oracleweblogic_server

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL