Prototype Pollution in Dojox
Published Mar 10, 2020
8.6
HIGHCVSS 3.1
EPSS 2.02%
Description
In affected versions of dojox (NPM package), the jqMix method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values. This has been patched in versions 1.11.10, 1.12.8, 1.13.7, 1.14.6, 1.15.3 and 1.16.2
Affected products
-
- Version < 1.11.10StatusaffectedConstraints-
- Version >= 1.12.0, < 1.12.8StatusaffectedConstraints-
- Version >= 1.13.0, < 1.13.7StatusaffectedConstraints-
- Version >= 1.14.0, < 1.14.6StatusaffectedConstraints-
- Version >= 1.15.0, < 1.15.3StatusaffectedConstraints-
- Version >= 1.16.0, < 1.16.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- < 1.11.10
- ≥ 1.12.0 · < 1.12.8
- ≥ 1.13.0 · < 1.13.7
- ≥ 1.14.0 · < 1.14.6
- ≥ 1.15.0 · < 1.15.3
- ≥ 1.16.0 · < 1.16.2
No data.
No Red Hat product state for this CVE.
dojox
npm
Introduced 1.13.0 Fixed 1.13.7dojox
npm
Introduced 1.14.0 Fixed 1.14.6dojox
npm
Introduced 1.15.0 Fixed 1.15.3dojox
npm
Introduced 1.16.0 Fixed 1.16.2dojox
npm
Introduced 0 Fixed 1.11.10dojox
npm
Introduced 1.12.0 Fixed 1.12.8
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | dojox | 1.13.0 | 1.13.7 |
| npm | dojox | 1.14.0 | 1.14.6 |
| npm | dojox | 1.15.0 | 1.15.3 |
| npm | dojox | 1.16.0 | 1.16.2 |
| npm | dojox | 0 | 1.11.10 |
| npm | dojox | 1.12.0 | 1.12.8 |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
1 other source (GHSA) ▾
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v5
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.02% (0.02018) | 80.21th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.98% (0.01976) | 77.82th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.20% (0.00196) | 57.53th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.20% (0.00196) | 55.64th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.95% (0.00954) | 36.37th | v2 (v2022.01.01) |
| Sep 2, 2022 | 0.95% (0.00954) | 34.50th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.95% (0.00954) | 32.50th | v2 (v2022.01.01) |
| Feb 4, 2022 | 5.74% (0.05736) | 77.22th | v2 (v2022.01.01) |
| Feb 3, 2022 | 3.63% (0.03630) | 71.73th | v1 |
| Jan 6, 2022 | 3.63% (0.03630) | 71.48th | v1 |
| Sep 1, 2021 | 0.83% (0.00833) | 57.50th | v1 |
| Apr 14, 2021 | 0.83% (0.00833) | 0.00th | v1 |
References (5)
- https://github.com/advisories/GHSA-3hw5-q855-g6cw Advisory
- https://github.com/dojo/dojox/commit/47d1b302b5b23d94e875b77b9b9a8c4f5622c9da x_refsource_MISCPatch
- https://github.com/dojo/dojox/security/advisories/GHSA-3hw5-q855-g6cw x_refsource_CONFIRMExploitThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/03/msg00012.html mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2020-5259
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-3hw5-q855-g6cw | Advisory | |
| https://github.com/dojo/dojox/commit/47d1b302b5b23d94e875b77b9b9a8c4f5622c9da | x_refsource_MISCPatch | |
| https://github.com/dojo/dojox/security/advisories/GHSA-3hw5-q855-g6cw | x_refsource_CONFIRMExploitThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2020/03/msg00012.html | mailing-listx_refsource_MLIST | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-5259 |
Change history (0)
No recorded changes yet.