CVE-2020-4051
In Dijit before versions 1.11.11, and greater than or equal to 1.12.0 and less than 1.12.9, and greater than or equal to 1.13.0 and less than 1.13.8, and greater than or equal to 1.14.0 and less than 1.14.7, and greater than or equal to 1.15.0 and less…
Does this matter?
Lower severity and a low EPSS score (1.18%). Track it; it rarely justifies an emergency change on its own.
Description
In Dijit before versions 1.11.11, and greater than or equal to 1.12.0 and less than 1.12.9, and greater than or equal to 1.13.0 and less than 1.13.8, and greater than or equal to 1.14.0 and less than 1.14.7, and greater than or equal to 1.15.0 and less than 1.15.4, and greater than or equal to 1.16.0 and less than 1.16.3, there is a cross-site scripting vulnerability in the Editor's LinkDialog plugin. This has been fixed in 1.11.11, 1.12.9, 1.13.8, 1.14.7, 1.15.4, 1.16.3.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.18% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- openjsf/dijit · debian/debian linux · netapp/active iq unified manager · netapp/oncommand insight · netapp/oncommand workflow automation · netapp/snapcenter
- Source
- security-advisories@github.com
References
- https://github.com/dojo/dijit/commit/462bdcd60d0333315fe69ab4709c894d78f61301Patch, Third Party Advisory
- https://github.com/dojo/dijit/security/advisories/GHSA-cxjc-r2fp-7mq6Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/01/msg00030.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20201023-0003/Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlPatch, Third Party Advisory
- https://github.com/dojo/dijit/commit/462bdcd60d0333315fe69ab4709c894d78f61301Patch, Third Party Advisory
- https://github.com/dojo/dijit/security/advisories/GHSA-cxjc-r2fp-7mq6Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/01/msg00030.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20201023-0003/Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.