CVE-2021-23450
Published Dec 17, 2021All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
Vendor/product archive
2 CVEs tagged to linuxfoundation / dojo — 0 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing…