Red Hat Bugzilla – Bug 1620362
CVE-2018-15494 dojo: Cross-site scripting (XSS) due to unescaped strings when editing rows in dojox/Grid/DataGrid
Last modified: 2018-08-23 01:20:04 EDT
Dojo toolkit before version 1.14 is vulnerable to a cross-site scripting (XSS) due to unescaped strings when editing rows in dojox/Grid/DataGrid. Upstream Patch: https://github.com/dojo/dojox/pull/283/commits/e92ee87750af8fbc7e474bb8e8661821aa9f88fa
Created dojo tracking bugs for this issue: Affects: epel-all [bug 1620364] Affects: fedora-all [bug 1620363]