Snyk reports security vulnerability in dojo prototype pollution
- Dominant language
- JavaScript
- Stars
- 15.8k
- Forks
- 3.9k
- Avg merge
- 4d 6h
- Merged PRs (30d)
- 34
Description
dojo Prototype Pollution
----
> copy and pasted from the Snyk security report
Vulnerability Score: 482
Introduced through dojo@1.10.4
Fixed in dojo@1.17.0
Exploit maturity: Proof of Concept
Detailed paths
Introduced through: dijit@1.10.4 › dojo@1.10.4
Fix: No remediation path available.
Security information
Factors contributing to the scoring:
Snyk: [CVSS 7.5](https://security.snyk.io/vuln/SNYK-JS-DOJO-1535223) - High Severity
NVD: [CVSS 9.8](https://nvd.nist.gov/vuln/detail/CVE-2021-23450) - Critical Severity
[dojo](https://dojo.io/) is a foundation package for the Dojo 1 Toolkit. While still being maintained, new development is primarily focused on modern Dojo. Affected versions of this package are vulnerable to Prototype Pollution via the setObject function.
Contributor guide
Research direction
The report names dojo@1.10.4, dijit@1.10.4, and the vulnerable setObject function, but no repository file or test. First trace how these dependencies enter Cesium and whether dojo can be upgraded to 1.17.0; done requires a confirmed remediation and a security regression check.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100