CVE-2020-4051

NameCVE-2020-4051
DescriptionIn Dijit before versions 1.11.11, and greater than or equal to 1.12.0 and less than 1.12.9, and greater than or equal to 1.13.0 and less than 1.13.8, and greater than or equal to 1.14.0 and less than 1.14.7, and greater than or equal to 1.15.0 and less than 1.15.4, and greater than or equal to 1.16.0 and less than 1.16.3, there is a cross-site scripting vulnerability in the Editor's LinkDialog plugin. This has been fixed in 1.11.11, 1.12.9, 1.13.8, 1.14.7, 1.15.4, 1.16.3.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitylow
Debian Bugs970000

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
dojo (PTS)buster1.14.2+dfsg1-1+deb10u2vulnerable
bullseye, sid1.15.4+dfsg1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
dojosource(unstable)1.15.4+dfsg1-1970000

Notes

[buster] - dojo <no-dsa> (Minor issue)
https://github.com/dojo/dijit/security/advisories/GHSA-cxjc-r2fp-7mq6
https://github.com/dojo/dijit/commit/462bdcd60d0333315fe69ab4709c894d78f61301

Search for package or bug name: Reporting problems