CVE-2021-23450: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
(updated )
All versions of package dojo is vulnerable to Prototype Pollution via the setObject function.
References
- github.com/dojo/dojo/blob/4c39c14349408fc8274e19b399ffc660512ed07c/_base/lang.js%23L172
- nvd.nist.gov/vuln/detail/CVE-2021-23450
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-2313036
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-2313035
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBDOJO-2313034
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2313033
- snyk.io/vuln/SNYK-JS-DOJO-1535223
Detect and mitigate CVE-2021-23450 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →