dojo: Cross-site scripting in i18n-test/unit.html and _base/i18nExhaustive.js
Published Sep 6, 2018
8.0
HIGHCVSS 3.0
EPSS 1.28%
Description
Dojo Dojo Objective Harness (DOH) version prior to version 1.14 contains a Cross Site Scripting (XSS) vulnerability in unit.html and testsDOH/_base/loader/i18n-exhaustive/i18n-test/unit.html and testsDOH/_base/i18nExhaustive.js in the DOH that can result in Victim attacked through their browser - deliver malware, steal HTTP cookies, bypass CORS trust. This attack appear to be exploitable via Victims are typically lured to a web site under the attacker's control; the XSS vulnerability on the target domain is silently exploited without the victim's knowledge. This vulnerability appears to have been fixed in 1.14.
Affected products
No data.
- ≤ 1.13.0
No data.
Red Hat Satellite 5
dojo
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Satellite 5 | dojo | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://access.redhat.com/security/cve/CVE-2018-1000665 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1626251 Issue Tracking
- https://dojotoolkit.org/blog/dojo-1-14-released x_refsource_CONFIRMPatchRelease NotesVendor Advisory
- https://github.com/advisories/GHSA-vmq9-cm7m-4p8p Advisory
- https://github.com/dojo/dojo/pull/307 x_refsource_CONFIRMThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-1000665
- https://www.cve.org/CVERecord?id=CVE-2018-1000665
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2018-1000665 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1626251 | Issue Tracking | |
| https://dojotoolkit.org/blog/dojo-1-14-released | x_refsource_CONFIRMPatchRelease NotesVendor Advisory | |
| https://github.com/advisories/GHSA-vmq9-cm7m-4p8p | Advisory | |
| https://github.com/dojo/dojo/pull/307 | x_refsource_CONFIRMThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-1000665 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-1000665 |
Change history (0)
No recorded changes yet.