Executive brief
A vulnerability exists in the Dojox library, a set of extensions for the Dojo JavaScript framework used to build web applications. An attacker can exploit this flaw to inject malicious properties into the application's core data structures. This can lead to unauthorized modification of application behavior or data, potentially compromising the integrity of the web service.
Technical details
The jqMix mixin method in the Dojox jQuery wrapper fails to properly sanitize property names during object merging. Specifically, it does not block the '__proto__' property, allowing an attacker to perform Prototype Pollution. By providing a specially crafted object to jqMix, a remote attacker can overwrite or add properties to the base Object prototype. This can lead to various impacts depending on the application's logic, including bypass of security checks or remote code execution in some environments. The vulnerability is fixed by explicitly checking for and rejecting the '__proto__' key during the mixin process.
Affected products
- Dojo dojox <1.11.10, 1.12.0-1.12.7, 1.13.0-1.13.6, 1.14.0-1.14.5, 1.15.0-1.15.2, 1.16.0-1.16.1
Timeline
- 2020-03-10: advisory
- 2020-03-10: disclosed
- 2020-03-10: patched