CVE-2010-2274

EUVD-2022-4593
Multiple open redirect vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, possibly related to dojo/resources/iframe_history.html, dojox/av/FLAudio.js, dojox/av/FLVideo.js, dojox/av/resources/audio.swf, dojox/av/resources/video.swf, util/buildscripts/jslib/build.js, util/buildscripts/jslib/buildUtil.js, and util/doh/runner.html.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 75%
Affected Products (NVD)
VendorProductVersion
dojotoolkitdojo
1.0
dojotoolkitdojo
1.0.1
dojotoolkitdojo
1.0.2
dojotoolkitdojo
1.1
dojotoolkitdojo
1.1.1
dojotoolkitdojo
1.2
dojotoolkitdojo
1.2.1
dojotoolkitdojo
1.2.2
dojotoolkitdojo
1.2.3
dojotoolkitdojo
1.3
dojotoolkitdojo
1.3.1
dojotoolkitdojo
1.3.2
dojotoolkitdojo
1.4
dojotoolkitdojo
1.4.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
dojo
bookworm
1.17.2+dfsg1-2.1
fixed
bullseye
1.15.4+dfsg1-1+deb11u1
fixed
sid
1.17.2+dfsg1-2.1
fixed
trixie
1.17.2+dfsg1-2.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dojo
dapper
dne
hardy
dne
jaunty
dne
karmic
dne
lucid
not-affected