QID 997325

Date Published: 2024-02-20

QID 997325: Java (Maven) Security Update for org.dojotoolkit:dojo (GHSA-mmjh-45vj-hfvf)

Multiple open redirect vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, possibly related to dojo/resources/iframe_history.html, dojox/av/FLAudio.js, dojox/av/FLVideo.js, dojox/av/resources/audio.swf, dojox/av/resources/video.swf, util/buildscripts/jslib/build.js, util/buildscripts/jslib/buildUtil.js, and util/doh/runner.html.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Refer to Github security advisory GHSA-mmjh-45vj-hfvf for updates and patch information.
    Vendor References

    CVEs related to QID 997325

    Software Advisories
    Advisory ID Software Component Link
    GHSA-mmjh-45vj-hfvf org.dojotoolkit:dojo URL Logo github.com/advisories/GHSA-mmjh-45vj-hfvf