QID 997325
Date Published: 2024-02-20
QID 997325: Java (Maven) Security Update for org.dojotoolkit:dojo (GHSA-mmjh-45vj-hfvf)
Multiple open redirect vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, possibly related to dojo/resources/iframe_history.html, dojox/av/FLAudio.js, dojox/av/FLVideo.js, dojox/av/resources/audio.swf, dojox/av/resources/video.swf, util/buildscripts/jslib/build.js, util/buildscripts/jslib/buildUtil.js, and util/doh/runner.html.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-mmjh-45vj-hfvf for updates and patch information.
Vendor References
- GHSA-mmjh-45vj-hfvf -
github.com/advisories/GHSA-mmjh-45vj-hfvf
CVEs related to QID 997325
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-mmjh-45vj-hfvf | org.dojotoolkit:dojo |
|