First published: Mon Jun 14 2010(Updated: )
Multiple open redirect vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, possibly related to dojo/resources/iframe_history.html, dojox/av/FLAudio.js, dojox/av/FLVideo.js, dojox/av/resources/audio.swf, dojox/av/resources/video.swf, util/buildscripts/jslib/build.js, util/buildscripts/jslib/buildUtil.js, and util/doh/runner.html.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.dojotoolkit:dojo | >=1.4.0<1.4.2 | 1.4.2 |
maven/org.dojotoolkit:dojo | >=1.3.0<1.3.3 | 1.3.3 |
maven/org.dojotoolkit:dojo | >=1.2.0<1.2.4 | 1.2.4 |
maven/org.dojotoolkit:dojo | >=1.1.0<1.1.2 | 1.1.2 |
maven/org.dojotoolkit:dojo | >=1.0.0<1.0.3 | 1.0.3 |
Dojo Toolkit | =1.0 | |
Dojo Toolkit | =1.0.1 | |
Dojo Toolkit | =1.0.2 | |
Dojo Toolkit | =1.1 | |
Dojo Toolkit | =1.1.1 | |
Dojo Toolkit | =1.2 | |
Dojo Toolkit | =1.2.1 | |
Dojo Toolkit | =1.2.2 | |
Dojo Toolkit | =1.2.3 | |
Dojo Toolkit | =1.3 | |
Dojo Toolkit | =1.3.1 | |
Dojo Toolkit | =1.3.2 | |
Dojo Toolkit | =1.4 | |
Dojo Toolkit | =1.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2274 has a medium severity level as it allows for open redirects, which can lead to phishing attacks.
To resolve CVE-2010-2274, upgrade to Dojo Toolkit version 1.0.3 or later, specifically 1.4.2 or above.
CVE-2010-2274 affects Dojo versions 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2.
Yes, CVE-2010-2274 can be exploited remotely by attackers to redirect users to arbitrary websites.
If upgrading is not feasible, consider implementing URL validation and additional security measures to mitigate the risks associated with CVE-2010-2274.