Executive brief
Dojo is a widely-used JavaScript toolkit for building web applications. A prototype pollution vulnerability in the setObject function allows attackers to inject arbitrary properties into JavaScript objects, potentially causing application logic bypasses, unauthorized data modification, or denial of service through object corruption.
Affected products
- Dojo Dojo 1.16.4 and earlier
Timeline
- 2021-12-17: disclosed
- 2022-01-05: advisory
- 2022-01-04: other: GitHub reviewed