CVE-2020-4051 Information

Description

In Dijit before versions 1.11.11 and greater than or equal to 1.12.0 and less than 1.12.9 and greater than or equal to 1.13.0 and less than 1.13.8 and greater than or equal to 1.14.0 and less than 1.14.7 and greater than or equal to 1.15.0 and less than 1.15.4 and greater than or equal to 1.16.0 and less than 1.16.3 there is a cross-site scripting vulnerability in the Editor’s LinkDialog plugin. This has been fixed in 1.11.11 1.12.9 1.13.8 1.14.7 1.15.4 1.16.3.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

Reference

https://github.com/dojo/dijit/commit/462bdcd60d0333315fe69ab4709c894d78f61301 https://github.com/dojo/dijit/security/advisories/GHSA-cxjc-r2fp-7mq6 https://security.netapp.com/advisory/ntap-20201023-0003/ https://www.oracle.com/security-alerts/cpuoct2020.html

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

REQUIRED

Confidentiality Impact

UNCHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

4.6

Share on: