← Back

CVE-2020-5258

nvd nist
Published: Mar 10, 2020Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD (Secondary)

Description

In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values. This has been patched in versions 1.12.8, 1.13.7, 1.14.6, 1.15.3 and 1.16.2

Affected (24)

Dojo
1 product
Debian Linux
8 products
Communications Policy Management
Documaker
Mysql
Primavera Unifier
Webcenter Sites
Weblogic Server
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Linuxfoundation
Before 1.11.10
From 1.12.0 to 1.12.8
From 1.13.0 to 1.13.7
From 1.14.0 to 1.14.6
From 1.15.0 to 1.15.3
From 1.16.0 to 1.16.2
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0
Configuration C
17 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.9.0
Version 12.5.0
Version 12.0.0.3.0
From 12.6.0 to 12.6.4
Oracle
From 7.3.0 to 7.3.29
From 7.4.0 to 7.4.28
From 7.5.0 to 7.5.18
From 7.6.0 to 7.6.14
From 8.0.0 to 8.0.20
Oracle
From 17.7 to 17.12
Version 18.8
Version 19.12
Version 20.12
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Oracle
Version 12.2.1.4.0
Version 14.1.1.0.0

References (22)

Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
ExploitThird Party Advisory
Source: security-advisories@github.com
Mailing ListThird Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
Source: security-advisories@github.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.