CVE-2020-4051
XSS in Dijit Editor's LinkDialog plugin
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
In Dijit before versions 1.11.11, and greater than or equal to 1.12.0 and less than 1.12.9, and greater than or equal to 1.13.0 and less than 1.13.8, and greater than or equal to 1.14.0 and less than 1.14.7, and greater than or equal to 1.15.0 and less than 1.15.4, and greater than or equal to 1.16.0 and less than 1.16.3, there is a cross-site scripting vulnerability in the Editor's LinkDialog plugin. This has been fixed in 1.11.11, 1.12.9, 1.13.8, 1.14.7, 1.15.4, 1.16.3.
En Dijit versiones anteriores a 1.11.11, y superiores o igual a 1.12.0 y menores a 1.12.9, y superiores o igual a 1.13.0 y menores a 1.13.8, y superiores o igual a 1.14.0 y menores a 1.14.7, y superiores o igual a 1.15.0 y menores a 1.15.4, y superiores o igual a 1.16.0 y menores a 1.16.3, se presenta una vulnerabilidad de tipo cross-site scripting en el plugin LinkDialog de Editor. Esto se ha corregido en las versiones 1.11.11, 1.12.9, 1.13.8, 1.14.7, 1.15.4, 1.16.3
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-12-30 CVE Reserved
- 2020-03-10 First Exploit
- 2020-06-15 CVE Published
- 2023-07-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://github.com/dojo/dijit/security/advisories/GHSA-cxjc-r2fp-7mq6 | Third Party Advisory | |
https://lists.debian.org/debian-lts-announce/2023/01/msg00030.html | Mailing List | |
https://security.netapp.com/advisory/ntap-20201023-0003 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/ossf-cve-benchmark/CVE-2020-4051 | 2020-03-10 |
URL | Date | SRC |
---|---|---|
https://github.com/dojo/dijit/commit/462bdcd60d0333315fe69ab4709c894d78f61301 | 2023-02-28 | |
https://www.oracle.com/security-alerts/cpuoct2020.html | 2023-02-28 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Openjsf Search vendor "Openjsf" | Dijit Search vendor "Openjsf" for product "Dijit" | < 1.11.11 Search vendor "Openjsf" for product "Dijit" and version " < 1.11.11" | - |
Affected
| ||||||
Openjsf Search vendor "Openjsf" | Dijit Search vendor "Openjsf" for product "Dijit" | >= 1.12.0 < 1.12.9 Search vendor "Openjsf" for product "Dijit" and version " >= 1.12.0 < 1.12.9" | - |
Affected
| ||||||
Openjsf Search vendor "Openjsf" | Dijit Search vendor "Openjsf" for product "Dijit" | >= 1.13.0 < 1.13.8 Search vendor "Openjsf" for product "Dijit" and version " >= 1.13.0 < 1.13.8" | - |
Affected
| ||||||
Openjsf Search vendor "Openjsf" | Dijit Search vendor "Openjsf" for product "Dijit" | >= 1.14.0 < 1.14.7 Search vendor "Openjsf" for product "Dijit" and version " >= 1.14.0 < 1.14.7" | - |
Affected
| ||||||
Openjsf Search vendor "Openjsf" | Dijit Search vendor "Openjsf" for product "Dijit" | >= 1.15.0 < 1.15.4 Search vendor "Openjsf" for product "Dijit" and version " >= 1.15.0 < 1.15.4" | - |
Affected
| ||||||
Openjsf Search vendor "Openjsf" | Dijit Search vendor "Openjsf" for product "Dijit" | >= 1.16.0 < 1.16.3 Search vendor "Openjsf" for product "Dijit" and version " >= 1.16.0 < 1.16.3" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 10.0 Search vendor "Debian" for product "Debian Linux" and version "10.0" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Active Iq Unified Manager Search vendor "Netapp" for product "Active Iq Unified Manager" | - | vmware_vsphere |
Affected
| ||||||
Netapp Search vendor "Netapp" | Active Iq Unified Manager Search vendor "Netapp" for product "Active Iq Unified Manager" | - | windows |
Affected
| ||||||
Netapp Search vendor "Netapp" | Oncommand Insight Search vendor "Netapp" for product "Oncommand Insight" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Oncommand Workflow Automation Search vendor "Netapp" for product "Oncommand Workflow Automation" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Snapcenter Search vendor "Netapp" for product "Snapcenter" | - | - |
Affected
|