Bug 49536 - dojo 1.12.1: multiple issues (ES 4.3)
dojo 1.12.1: multiple issues (ES 4.3)
Status: CLOSED WONTFIX
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 4.3
Other Linux
: P5 normal (vote)
: UCS 4.3 extended security
Assigned To: UCS maintainers
Erik Damrose
https://www.cvedetails.com/vulnerabil...
:
Depends on: 48963
Blocks:
  Show dependency treegraph
 
Reported: 2019-05-23 17:57 CEST by Arvid Requate
Modified: 2021-06-14 09:55 CEST (History)
6 users (show)

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review: Yes
Ticket number:
Bug group (optional): Security
Max CVSS v3 score: 7.5 - 8 (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Arvid Requate univentionstaff 2019-05-23 17:57:58 CEST
+++ This bug was initially created as a clone of Bug #49535 +++

The snyk npm monitor currently shows these vulnerabilities for the dojo toolkit:

* unescaped string injection in dojox/Grid/DataGrid (CVE-2018-15494)
  https://access.redhat.com/security/cve/cve-2018-15494

* https://security-tracker.debian.org/tracker/CVE-2018-1000665
  https://access.redhat.com/security/cve/cve-2018-1000665

* https://snyk.io/vuln/npm:dojo:20180818
Comment 4 Erik Damrose univentionstaff 2020-11-19 09:19:15 CET
Resolved: Package imported and copied to extsec4.3 scope
Comment 5 Erik Damrose univentionstaff 2020-11-27 16:39:26 CET
Reopen: Wrong comment above, i mistakenly edited this bug with several others for ES 4.3.
We have to wait for the fix in UCS 4.4 / UCS 5 before we can backport dojo at this bug.
I fixed the "depends on" bugnumber.
Comment 6 Ingo Steuwer univentionstaff 2021-05-14 16:49:03 CEST
should be still relevant for UCS 4.4
Comment 7 Ingo Steuwer univentionstaff 2021-05-14 16:49:43 CEST
(In reply to Ingo Steuwer from comment #6)
> should be still relevant for UCS 4.4

no, wrong bug -> still UCS 4.3
Comment 8 Erik Damrose univentionstaff 2021-06-14 09:55:22 CEST
Extended security maintenance for UCS 4.3 ended on 31 May 2021. As the dojo update was not yet done in UCS 4.4 (bug 52138) the fix could not be backported to UCS 4.3 extsec.