Publish Advisories

GHSA-mmjh-45vj-hfvf
GHSA-mmjh-45vj-hfvf
This commit is contained in:
advisory-database[bot]
2024-02-08 15:50:30 +00:00
parent 72fa5a61fb
commit e24cc37348
2 changed files with 174 additions and 79 deletions
@@ -0,0 +1,174 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mmjh-45vj-hfvf",
"modified": "2024-02-08T15:49:12Z",
"published": "2022-05-17T05:50:10Z",
"aliases": [
"CVE-2010-2274"
],
"summary": "Dojo Open Redirect vulnerability",
"details": "Multiple open redirect vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, possibly related to dojo/resources/iframe_history.html, dojox/av/FLAudio.js, dojox/av/FLVideo.js, dojox/av/resources/audio.swf, dojox/av/resources/video.swf, util/buildscripts/jslib/build.js, util/buildscripts/jslib/buildUtil.js, and util/doh/runner.html.",
"severity": [
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.dojotoolkit:dojo"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.0.0"
},
{
"fixed": "1.0.3"
}
]
}
]
},
{
"package": {
"ecosystem": "Maven",
"name": "org.dojotoolkit:dojo"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.1.0"
},
{
"fixed": "1.1.2"
}
]
}
]
},
{
"package": {
"ecosystem": "Maven",
"name": "org.dojotoolkit:dojo"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.2.0"
},
{
"fixed": "1.2.4"
}
]
}
]
},
{
"package": {
"ecosystem": "Maven",
"name": "org.dojotoolkit:dojo"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.3.0"
},
{
"fixed": "1.3.3"
}
]
}
]
},
{
"package": {
"ecosystem": "Maven",
"name": "org.dojotoolkit:dojo"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.4.0"
},
{
"fixed": "1.4.2"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2010-2274"
},
{
"type": "PACKAGE",
"url": "https://github.com/cometd/dojo-maven"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20100617172214/http://secunia.com/advisories/40007"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20100629020444/http://secunia.com/advisories/38964"
},
{
"type": "WEB",
"url": "http://dojotoolkit.org/blog/post/dylan/2010/03/dojo-security-advisory/"
},
{
"type": "WEB",
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21431472"
},
{
"type": "WEB",
"url": "http://www-1.ibm.com/support/docview.wss?uid=swg1LO50833"
},
{
"type": "WEB",
"url": "http://www-1.ibm.com/support/docview.wss?uid=swg1LO50849"
},
{
"type": "WEB",
"url": "http://www-1.ibm.com/support/docview.wss?uid=swg1LO50856"
},
{
"type": "WEB",
"url": "http://www-1.ibm.com/support/docview.wss?uid=swg1LO50896"
},
{
"type": "WEB",
"url": "http://www-1.ibm.com/support/docview.wss?uid=swg1LO50932"
},
{
"type": "WEB",
"url": "http://www-1.ibm.com/support/docview.wss?uid=swg1LO50958"
},
{
"type": "WEB",
"url": "http://www-1.ibm.com/support/docview.wss?uid=swg1LO50994"
}
],
"database_specific": {
"cwe_ids": [
"CWE-601"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-02-08T15:49:12Z",
"nvd_published_at": "2010-06-15T14:30:00Z"
}
}
@@ -1,79 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mmjh-45vj-hfvf",
"modified": "2022-05-17T05:50:10Z",
"published": "2022-05-17T05:50:10Z",
"aliases": [
"CVE-2010-2274"
],
"details": "Multiple open redirect vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, possibly related to dojo/resources/iframe_history.html, dojox/av/FLAudio.js, dojox/av/FLVideo.js, dojox/av/resources/audio.swf, dojox/av/resources/video.swf, util/buildscripts/jslib/build.js, util/buildscripts/jslib/buildUtil.js, and util/doh/runner.html.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2010-2274"
},
{
"type": "WEB",
"url": "http://dojotoolkit.org/blog/post/dylan/2010/03/dojo-security-advisory/"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/38964"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/40007"
},
{
"type": "WEB",
"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21431472"
},
{
"type": "WEB",
"url": "http://www-1.ibm.com/support/docview.wss?uid=swg1LO50833"
},
{
"type": "WEB",
"url": "http://www-1.ibm.com/support/docview.wss?uid=swg1LO50849"
},
{
"type": "WEB",
"url": "http://www-1.ibm.com/support/docview.wss?uid=swg1LO50856"
},
{
"type": "WEB",
"url": "http://www-1.ibm.com/support/docview.wss?uid=swg1LO50896"
},
{
"type": "WEB",
"url": "http://www-1.ibm.com/support/docview.wss?uid=swg1LO50932"
},
{
"type": "WEB",
"url": "http://www-1.ibm.com/support/docview.wss?uid=swg1LO50958"
},
{
"type": "WEB",
"url": "http://www-1.ibm.com/support/docview.wss?uid=swg1LO50994"
},
{
"type": "WEB",
"url": "http://www.vupen.com/english/advisories/2010/1281"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2010-06-15T14:30:00Z"
}
}