CVE-2021-23450
published 2021-12-17CVE-2021-23450: All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
PriorityP261critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
30.37%
98.0th percentile
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | dojo | < dojo 1.17.2+dfsg1-1 (bookworm) | dojo 1.17.2+dfsg1-1 (bookworm) |
| linuxfoundation | dojo | < unspecified | unspecified |
| linuxfoundation | dojo | < 1.17.0 | 1.17.0 |
| linuxfoundation | dojo | >= 0 < 1.15.4+dfsg1-1+deb11u1 | 1.15.4+dfsg1-1+deb11u1 |
| linuxfoundation | dojo | >= 0 < 1.17.2+dfsg1-1 | 1.17.2+dfsg1-1 |
| linuxfoundation | dojo | >= 0 < 1.17.2+dfsg1-1 | 1.17.2+dfsg1-1 |
| linuxfoundation | dojo | >= 0 < 1.17.2+dfsg1-1 | 1.17.2+dfsg1-1 |
| linuxfoundation | dojo | >= 0 < 1.15.4+dfsg1-1ubuntu0.1 | 1.15.4+dfsg1-1ubuntu0.1 |
| linuxfoundation | dojo | >= 0 < 1.10.4+dfsg-2ubuntu0.1~esm1 | 1.10.4+dfsg-2ubuntu0.1~esm1 |
| linuxfoundation | dojo | >= 0 < 1.15.0+dfsg1-1ubuntu0.1~esm1 | 1.15.0+dfsg1-1ubuntu0.1~esm1 |
| linuxfoundation | dojo | 0 – 1.16.4 | — |
| oracle | communications_policy_management | — | — |
| oracle | primavera_unifier | — | — |
| oracle | primavera_unifier | — | — |
| oracle | primavera_unifier | — | — |
| oracle | primavera_unifier | — | — |
| oracle | primavera_unifier | 17.7 – 17.12 | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Prototype Pollution vulnerability is triggered via the `setObject` function in the dojo package — monitor for unexpected prototype chain manipulation through this function. ↗
- →Exploitation vector is remote over HTTP — inspect HTTP traffic targeting applications using dojo's setObject function for prototype pollution payloads (e.g., `__proto__`, `constructor`, `prototype` keys in request parameters). ↗
- ·All versions of dojo are affected; fixed versions are 1.17.2+dfsg1-1 (bookworm/forky/sid/trixie) and 1.15.4+dfsg1-1+deb11u1 (bullseye) on Debian. ↗
- ·Red Hat Enterprise Linux 7 (ipa package) is confirmed not affected. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_oracle9.8HIGH
vendor_ubuntu9.8CRITICAL
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Dojo vulnerabilities
vendor_ubuntu·2025-06-16·CVSS 9.8
CVE-2020-4051 [CRITICAL] Dojo vulnerabilities
Title: Dojo vulnerabilities
Summary: Several security issues were fixed in Dojo.
It was discovered that Dojo did not correctly handle DataGrids. An
attacker could possibly use this issue to execute arbitrary code. This
issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
(CVE-2018-15494)
It was discovered that Dojo was vulnerable to prototype pollution. An
attacker could possibly use this issue to execute arbitrary code.
(CVE-2021-23450)
Jonathan Leitschuh discovered that Dojo did not correctly sanitize
certain inputs. An attacker could possibly use this issue to execute a
cross-site scripting (XSS) attack. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
(CVE-2019-10785, CVE-2020-4051)
Instructions: In general, a standard system update will make
Oracle
Oracle Oracle Commerce Risk Matrix: Asset Manager (dojo) — CVE-2021-23450
vendor_oracle·2025-04-15·CVSS 9.8
CVE-2021-23450 [HIGH] Oracle Oracle Commerce Risk Matrix: Asset Manager (dojo) — CVE-2021-23450
Oracle Oracle Commerce Risk Matrix: Asset Manager (dojo) vulnerability
CVE: CVE-2021-23450
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2025 (APR 2025)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Framework (dojo) — CVE-2021-23450
vendor_oracle·2022-10-15·CVSS 9.8
CVE-2021-23450 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Framework (dojo) — CVE-2021-23450
Oracle Oracle Communications Applications Risk Matrix: Framework (dojo) vulnerability
CVE: CVE-2021-23450
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Sample apps (Dojo) — CVE-2021-23450
vendor_oracle·2022-07-15·CVSS 9.8
CVE-2021-23450 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Sample apps (Dojo) — CVE-2021-23450
Oracle Oracle Fusion Middleware Risk Matrix: Sample apps (Dojo) vulnerability
CVE: CVE-2021-23450
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Communications Risk Matrix: CMP (dojo) — CVE-2021-23450
vendor_oracle·2022-04-15·CVSS 9.8
CVE-2021-23450 [HIGH] Oracle Oracle Communications Risk Matrix: CMP (dojo) — CVE-2021-23450
Oracle Oracle Communications Risk Matrix: CMP (dojo) vulnerability
CVE: CVE-2021-23450
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Red Hat
dojo: prototype pollution via the setObject function
vendor_redhat·2021-12-08·CVSS 7.5
CVE-2021-23450 [HIGH] CWE-915 dojo: prototype pollution via the setObject function
dojo: prototype pollution via the setObject function
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
Package: ipa (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2021-23450: dojo - All versions of package dojo are vulnerable to Prototype Pollution via the setOb...
vendor_debian·2021·CVSS 7.5
CVE-2021-23450 [HIGH] CVE-2021-23450: dojo - All versions of package dojo are vulnerable to Prototype Pollution via the setOb...
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
Scope: local
bookworm: resolved (fixed in 1.17.2+dfsg1-1)
bullseye: resolved (fixed in 1.15.4+dfsg1-1+deb11u1)
forky: resolved (fixed in 1.17.2+dfsg1-1)
sid: resolved (fixed in 1.17.2+dfsg1-1)
trixie: resolved (fixed in 1.17.2+dfsg1-1)
OSV
dojo vulnerabilities
osv·2025-06-16·CVSS 9.8
CVE-2018-15494 [CRITICAL] dojo vulnerabilities
dojo vulnerabilities
It was discovered that Dojo did not correctly handle DataGrids. An
attacker could possibly use this issue to execute arbitrary code. This
issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
(CVE-2018-15494)
It was discovered that Dojo was vulnerable to prototype pollution. An
attacker could possibly use this issue to execute arbitrary code.
(CVE-2021-23450)
Jonathan Leitschuh discovered that Dojo did not correctly sanitize
certain inputs. An attacker could possibly use this issue to execute a
cross-site scripting (XSS) attack. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
(CVE-2019-10785, CVE-2020-4051)
GHSA
Prototype Pollution in dojo
ghsa·2022-01-05
CVE-2021-23450 [HIGH] CWE-1321 Prototype Pollution in dojo
Prototype Pollution in dojo
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
OSV
Prototype Pollution in dojo
osv·2022-01-05
CVE-2021-23450 [HIGH] Prototype Pollution in dojo
Prototype Pollution in dojo
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
OSV
CVE-2021-23450: All versions of package dojo are vulnerable to Prototype Pollution via the setObject function
osv·2021-12-17·CVSS 9.8
CVE-2021-23450 [CRITICAL] CVE-2021-23450: All versions of package dojo are vulnerable to Prototype Pollution via the setObject function
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/dojo/dojo/blob/4c39c14349408fc8274e19b399ffc660512ed07c/_base/lang.js%23L172https://lists.debian.org/debian-lts-announce/2023/01/msg00030.htmlhttps://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-2313036https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-2313035https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBDOJO-2313034https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2313033https://snyk.io/vuln/SNYK-JS-DOJO-1535223https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://github.com/dojo/dojo/blob/4c39c14349408fc8274e19b399ffc660512ed07c/_base/lang.js%23L172https://lists.debian.org/debian-lts-announce/2023/01/msg00030.htmlhttps://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-2313036https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-2313035https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBDOJO-2313034https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2313033https://snyk.io/vuln/SNYK-JS-DOJO-1535223https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.html
2021-12-17
Published