CesiumGS / CesiumGS/cesium

Snyk reports security vulnerability in dojo prototype pollution

Open
#11,243 2 comments 0 reactions 0 assignees View on GitHub
category - packaging & tooling
Dominant language
JavaScript
Stars
15.8k
Forks
3.9k
Avg merge
4d 6h
Merged PRs (30d)
34

Description

dojo Prototype Pollution
----
> copy and pasted from the Snyk security report

Vulnerability Score: 482

Introduced through dojo@1.10.4
Fixed in dojo@1.17.0

Exploit maturity: Proof of Concept

Detailed paths
Introduced through: dijit@1.10.4 › dojo@1.10.4
Fix: No remediation path available.

Security information
Factors contributing to the scoring:

Snyk: [CVSS 7.5](https://security.snyk.io/vuln/SNYK-JS-DOJO-1535223) - High Severity
NVD: [CVSS 9.8](https://nvd.nist.gov/vuln/detail/CVE-2021-23450) - Critical Severity

[dojo](https://dojo.io/) is a foundation package for the Dojo 1 Toolkit. While still being maintained, new development is primarily focused on modern Dojo. Affected versions of this package are vulnerable to Prototype Pollution via the setObject function.

Contributor guide

Open the contributing guide

Research direction

The report names dojo@1.10.4, dijit@1.10.4, and the vulnerable setObject function, but no repository file or test. First trace how these dependencies enter Cesium and whether dojo can be upgraded to 1.17.0; done requires a confirmed remediation and a security regression check.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.