Dojo toolkit before version 1.14 is vulnerable to a cross-site scripting (XSS) due to unescaped strings when editing rows in dojox/Grid/DataGrid. Upstream Patch: https://github.com/dojo/dojox/pull/283/commits/e92ee87750af8fbc7e474bb8e8661821aa9f88fa
Created dojo tracking bugs for this issue: Affects: epel-all [bug 1620364] Affects: fedora-all [bug 1620363]
Statement: Red Hat Enterprise Satellite 5 is now in Maintenance Support 2 phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Satellite 5 Life Cycle: https://access.redhat.com/support/policy/updates/satellite.