CVE-2021-23450

Related Vulnerabilities: CVE-2021-23450  

All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.

Description

The MITRE CVE dictionary describes this issue as:

All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.

Additional Information

  • Bugzilla 2035012: CVE-2021-23450 dojo: prototype pollution via the setObject function
  • CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes
  • FAQ: Frequently asked questions about CVE-2021-23450