漏洞信息详情
dojo 注入漏洞
漏洞简介
dojo是一款JavaScript工具箱,它包含实用程序和UI组件等。
dojox中存在注入漏洞。攻击者可利用该漏洞覆盖或污染基本对象的JavaScript应用程序对象原型。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://github.com/dojo/dojox/security/advisories/GHSA-3hw5-q855-g6cw
参考网址
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2020/03/msg00012.html
来源:MISC
链接:https://github.com/dojo/dojox/commit/47d1b302b5b23d94e875b77b9b9a8c4f5622c9da
来源:CONFIRM
链接:https://github.com/dojo/dojox/security/advisories/GHSA-3hw5-q855-g6cw
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6455281
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-datapower-gateway-affected-by-multiple-vulnerabilities-in-dojo/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-dojo-affect-ibm-spectrum-protect-operations-center-cve-2020-5259-cve-2020-5258/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-dojo-affect-ibm-spectrum-protect-for-virtual-environments-cve-2020-5259-cve-2020-5258/
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2020-5259
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.0877/
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/dojo-memory-corruption-via-Prototype-Pollution-31771
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-content-navigator-is-vulnerable-to-a-prototype-pollution-vulnerability/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-affect-ibm-cloud-pak-for-automation/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-tivoli-netcool-impact-is-affected-by-ibm-dojo-toolkit-vulnerabilities-cve-2020-5258-cve-2020-5259/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-guardium-is-affected-by-multiple-vulnerabilities-6/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-guardium-is-affected-by-multiple-vulnerabilities-4/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-guardium-is-affected-by-multiple-vulnerabilities-5/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-dojo-may-affect-ibm-business-automation-workflow-and-ibm-business-process-manager-bpm/
受影响实体
暂无
补丁
- dojox 注入漏洞的修复措施<!--2020-3-10-->
还没有评论,来说两句吧...