QID 980705
QID 980705: Nodejs (npm) Security Update for dojo (GHSA-39cx-xcwj-3rc4)
Affected versions of `dojo` are susceptible to a cross-site scripting vulnerability in the `dijit.Editor` and `textarea` components, which execute their contents as Javascript, even when sanitized.
## Recommendation
Update to version 1.1 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-39cx-xcwj-3rc4 for updates pertaining to this vulnerability.
Vendor References
- GHSA-39cx-xcwj-3rc4 -
github.com/advisories/GHSA-39cx-xcwj-3rc4
CVEs related to QID 980705
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-39cx-xcwj-3rc4 | dojo |
|