{"id":"GHSA-3hw5-q855-g6cw","summary":"Prototype Pollution in Dojox","details":"The Dojox jQuery wrapper `jqMix` mixin method is vulnerable to Prototype Pollution. \n\nAffected Area:\n```\n//https://github.com/dojo/dojox/blob/master/jq.js#L442\n\t\tvar tobj = {};\n\t\tfor(var x in props){\n\t\t\t// the \"tobj\" condition avoid copying properties in \"props\"\n\t\t\t// inherited from Object.prototype.  For example, if obj has a custom\n\t\t\t// toString() method, don't overwrite it with the toString() method\n\t\t\t// that props inherited from Object.prototype\n\t\t\tif((tobj[x] === undefined || tobj[x] != props[x]) && props[x] !== undefined && obj != props[x]){\n\t\t\t\tif(dojo.isObject(obj[x]) && dojo.isObject(props[x])){\n\t\t\t\t\tif(dojo.isArray(props[x])){\n\t\t\t\t\t\tobj[x] = props[x];\n\t\t\t\t\t}else{\n\t\t\t\t\t\tobj[x] = jqMix(obj[x], props[x]);\n\t\t\t\t\t}\n\t\t\t\t}else{\n\t\t\t\t\tobj[x] = props[x];\n\t\t\t\t}\n```","aliases":["CVE-2020-5259"],"modified":"2026-07-08T06:28:01.561324837Z","published":"2020-03-10T18:03:32Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-03-10T18:02:07Z","nvd_published_at":null,"cwe_ids":["CWE-94"],"severity":"LOW"},"references":[{"type":"WEB","url":"https://github.com/dojo/dojox/security/advisories/GHSA-3hw5-q855-g6cw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-5259"},{"type":"WEB","url":"https://github.com/dojo/dojox/commit/47d1b302b5b23d94e875b77b9b9a8c4f5622c9da"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2020/03/msg00012.html"}],"affected":[{"package":{"name":"dojox","ecosystem":"npm","purl":"pkg:npm/dojox"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.11.10"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/03/GHSA-3hw5-q855-g6cw/GHSA-3hw5-q855-g6cw.json"}},{"package":{"name":"dojox","ecosystem":"npm","purl":"pkg:npm/dojox"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.12.0"},{"fixed":"1.12.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/03/GHSA-3hw5-q855-g6cw/GHSA-3hw5-q855-g6cw.json"}},{"package":{"name":"dojox","ecosystem":"npm","purl":"pkg:npm/dojox"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.13.0"},{"fixed":"1.13.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/03/GHSA-3hw5-q855-g6cw/GHSA-3hw5-q855-g6cw.json"}},{"package":{"name":"dojox","ecosystem":"npm","purl":"pkg:npm/dojox"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.14.0"},{"fixed":"1.14.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/03/GHSA-3hw5-q855-g6cw/GHSA-3hw5-q855-g6cw.json"}},{"package":{"name":"dojox","ecosystem":"npm","purl":"pkg:npm/dojox"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.15.0"},{"fixed":"1.15.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/03/GHSA-3hw5-q855-g6cw/GHSA-3hw5-q855-g6cw.json"}},{"package":{"name":"dojox","ecosystem":"npm","purl":"pkg:npm/dojox"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.16.0"},{"fixed":"1.16.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/03/GHSA-3hw5-q855-g6cw/GHSA-3hw5-q855-g6cw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N"}]}