CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2020-5258: dojo before 1.11.10 (exclusive), from 1.12.0 (inclusive), before 1.12.8 (exclusive), from 1.13.0 (inclusive), before…

CVE-2020-5258. CVSS 3.1 base score 7.7 (HIGH, Vendor/CNA). EPSS 0.04023 (percentile 0.90321), scored 2026-10-08.

Affected technology

dojo · before 1.11.10 (exclusive)
linuxfoundation

dojo · from 1.12.0 (inclusive), before 1.12.8 (exclusive)
linuxfoundation

dojo · from 1.13.0 (inclusive), before 1.13.7 (exclusive)
linuxfoundation

dojo · from 1.14.0 (inclusive), before 1.14.6 (exclusive)
linuxfoundation

dojo · from 1.15.0 (inclusive), before 1.15.3 (exclusive)
linuxfoundation

dojo · from 1.16.0 (inclusive), before 1.16.2 (exclusive)
linuxfoundation

debian linux · 8.0
debian

communications application session controller · 3.9.0
oracle

communications policy management · 12.5.0
oracle

communications pricing design center · 12.0.0.3.0
oracle

documaker · from 12.6.0 (inclusive), through 12.6.4 (inclusive)
oracle

mysql · from 7.3.0 (inclusive), through 7.3.29 (inclusive)
oracle

mysql · from 7.4.0 (inclusive), through 7.4.28 (inclusive)
oracle

mysql · from 7.5.0 (inclusive), through 7.5.18 (inclusive)
oracle

mysql · from 7.6.0 (inclusive), through 7.6.14 (inclusive)
oracle

mysql · from 8.0.0 (inclusive), through 8.0.20 (inclusive)
oracle

primavera unifier · from 17.7 (inclusive), through 17.12 (inclusive)
oracle

primavera unifier · 18.8
oracle

primavera unifier · 19.12
oracle

primavera unifier · 20.12
oracle

webcenter sites · 12.2.1.3.0
oracle

webcenter sites · 12.2.1.4.0
oracle

weblogic server · 12.2.1.4.0
oracle

weblogic server · 14.1.1.0.0
oracle

dojo · < 1.12.8, >= 1.13.0, < 1.13.7, >= 1.14.0, < 1.14.6, >= 1.15.0, < 1.15.3, >= 1.16.0, < 1.16.2
dojo

Description’s affected range: versions of dojo (NPM package), the deepCopy method

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · Low privileges required · User interaction required

Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

Vendor/CNA’s CVSS 3.1 assessment (base score 7.7/10) rates confidentiality and integrity impact as high; availability impact as none. NVD’s CVSS 3.1 assessment (base score 7.5/10) rates confidentiality and availability impact as none; integrity impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

Published

CWE
CWE-94, CWE-1321
CCR priority
31.8 /100 (P4)
CVSS 3.1
7.7 /10 · CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N · Vendor/CNA
EPSS
0.04023 · percentile 0.90321 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2020-5258.html