Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33403
HistoryDec 20, 2021 - 11:36 a.m.

Prototype Pollution

2021-12-2011:36:38
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
57

0.01 Low

EPSS

Percentile

83.8%

dojo is vulnerable to prototype pollution. The vulnerability exists in setObject function of lang.js due to lack of object validations which allows an attacker to inject arbitrary object properties which can potentially lead to execution of arbitrary code.