CVE-2010-2274

Dojo Open Redirect vulnerability in maven/org.dojotoolkit/dojo

Identifiers

GHSA-mmjh-45vj-hfvf, CVE-2010-2274

Package Slug

maven/org.dojotoolkit/dojo

Vulnerability

Dojo Open Redirect vulnerability

Description

Multiple open redirect vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, possibly related to dojo/resources/iframe_history.html, dojox/av/FLAudio.js, dojox/av/FLVideo.js, dojox/av/resources/audio.swf, dojox/av/resources/video.swf, util/buildscripts/jslib/build.js, util/buildscripts/jslib/buildUtil.js, and util/doh/runner.html.

Affected Versions

All versions starting from 1.0.0 before 1.0.3, all versions starting from 1.1.0 before 1.1.2, all versions starting from 1.2.0 before 1.2.4, all versions starting from 1.3.0 before 1.3.3, all versions starting from 1.4.0 before 1.4.2

Solution

Upgrade to versions 1.0.3, 1.1.2, 1.2.4, 1.3.3, 1.4.2 or above.

Last Modified

2024-02-09

source