HIGH · 7.7

CVE-2020-5258

In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language c...

Vulnerability Description

In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values. This has been patched in versions 1.12.8, 1.13.7, 1.14.6, 1.15.3 and 1.16.2

CVSS Score

7.7

HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
LinuxfoundationDojo< 1.11.10
DebianDebian Linux8.0
OracleCommunications Application Session Controller3.9.0
OracleCommunications Policy Management12.5.0
OracleCommunications Pricing Design Center12.0.0.3.0
OracleDocumaker>= 12.6.0, <= 12.6.4
OracleMysql>= 7.3.0, <= 7.3.29
OraclePrimavera Unifier>= 17.7, <= 17.12
OracleWebcenter Sites12.2.1.3.0
OracleWeblogic Server12.2.1.4.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-5258?

CVE-2020-5258 is a vulnerability with a CVSS score of 7.7 (HIGH). In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language c...

How severe is CVE-2020-5258?

CVE-2020-5258 has been rated HIGH with a CVSS base score of 7.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-5258?

Check the references section above for vendor advisories and patch information. Affected products include: Linuxfoundation Dojo, Debian Debian Linux, Oracle Communications Application Session Controller, Oracle Communications Policy Management, Oracle Communications Pricing Design Center.