CVE-2020-5258 (CNNVD-202003-462)
中文标题:
dojo 代码注入漏洞
英文标题:
Prototype pollution in dojo
漏洞描述
中文描述:
dojo是一款JavaScript工具箱,它包含实用程序和UI组件等。 dojo中的deepCopy方法存在代码注入漏洞。攻击者可利用该漏洞覆盖或污染基本对象的JavaScript应用程序对象原型。以下产品及版本受到影响:dojo 1.12.8之前版本,1.13.0及之后版本(1.13.7版本已修复),1.14.0及之后版本(1.14.6版本已修复),1.15.0及之后版本(1.15.3版本已修复),1.16.0及之后版本(1.16.2版本已修复)。
英文描述:
In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values. This has been patched in versions 1.12.8, 1.13.7, 1.14.6, 1.15.3 and 1.16.2
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| dojo | dojo | < 1.12.8 | - | - |
cpe:2.3:a:dojo:dojo:<_1.12.8:*:*:*:*:*:*:*
|
| dojo | dojo | >= 1.13.0, < 1.13.7 | - | - |
cpe:2.3:a:dojo:dojo:>=_1.13.0,_<_1.13.7:*:*:*:*:*:*:*
|
| dojo | dojo | >= 1.14.0, < 1.14.6 | - | - |
cpe:2.3:a:dojo:dojo:>=_1.14.0,_<_1.14.6:*:*:*:*:*:*:*
|
| dojo | dojo | >= 1.15.0, < 1.15.3 | - | - |
cpe:2.3:a:dojo:dojo:>=_1.15.0,_<_1.15.3:*:*:*:*:*:*:*
|
| dojo | dojo | >= 1.16.0, < 1.16.2 | - | - |
cpe:2.3:a:dojo:dojo:>=_1.16.0,_<_1.16.2:*:*:*:*:*:*:*
|
| linuxfoundation | dojo | * | - | - |
cpe:2.3:a:linuxfoundation:dojo:*:*:*:*:*:node.js:*:*
|
| debian | debian_linux | 8.0 | - | - |
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
|
| oracle | communications_application_session_controller | 3.9.0 | - | - |
cpe:2.3:a:oracle:communications_application_session_controller:3.9.0:*:*:*:*:*:*:*
|
| oracle | communications_policy_management | 12.5.0 | - | - |
cpe:2.3:a:oracle:communications_policy_management:12.5.0:*:*:*:*:*:*:*
|
| oracle | communications_pricing_design_center | 12.0.0.3.0 | - | - |
cpe:2.3:a:oracle:communications_pricing_design_center:12.0.0.3.0:*:*:*:*:*:*:*
|
| oracle | documaker | * | - | - |
cpe:2.3:a:oracle:documaker:*:*:*:*:*:*:*:*
|
| oracle | mysql | * | - | - |
cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*
|
| oracle | primavera_unifier | * | - | - |
cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*
|
| oracle | primavera_unifier | 18.8 | - | - |
cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:*
|
| oracle | primavera_unifier | 19.12 | - | - |
cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:*
|
| oracle | primavera_unifier | 20.12 | - | - |
cpe:2.3:a:oracle:primavera_unifier:20.12:*:*:*:*:*:*:*
|
| oracle | webcenter_sites | 12.2.1.3.0 | - | - |
cpe:2.3:a:oracle:webcenter_sites:12.2.1.3.0:*:*:*:*:*:*:*
|
| oracle | webcenter_sites | 12.2.1.4.0 | - | - |
cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*
|
| oracle | weblogic_server | 12.2.1.4.0 | - | - |
cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
|
| oracle | weblogic_server | 14.1.1.0.0 | - | - |
cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
CVSS评分详情
3.1 (cna)
HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2020-5258 |
2025-11-11 15:20:39 | 2025-11-11 07:36:24 |
| NVD | nvd_CVE-2020-5258 |
2025-11-11 14:56:56 | 2025-11-11 07:44:47 |
| CNNVD | cnnvd_CNNVD-202003-462 |
2025-11-11 15:10:23 | 2025-11-11 07:55:46 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 代码注入
- cnnvd_id: 未提取 -> CNNVD-202003-462
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 5 -> 20
- data_sources: ['cve'] -> ['cve', 'nvd']