---
title: "CVE-2021-23450"
canonical: "https://kb.cynergy.app/space/MD/923730337/CVE-2021-23450"
format: markdown
---
**Description**

Certain versions of [Dojo](https://cve.report/software/linuxfoundation/dojo) from [Linuxfoundation](https://cve.report/vendor/linuxfoundation) contain the following vulnerability:

All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.

**Published On**

12/17/2021

**Updated On**

07/25/2022

**Trending**

FALSE

**CWE**

<u>[CWE-1321](http://cwe.mitre.org/data/definitions/1321.html)</u>

**Exploit**

[https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-2313036](https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-2313036) 

 

**Mitigation:**

![image](media://56a70450-b7ad-4dec-a34c-2700c326a610)

Cynergy has an automated mitigation capability that requires integration with your WAF provider.

Once integrated, you can request “Protect with WAF”

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately</span>

 

**Remediation**

Upgrade `org.webjars:dojo` to version 1.17.2 or higher.

**References**

|  |  |  |
| --- | --- | --- |
| Prototype Pollution in org.webjars.bowergithub.dojo:dojo | Snyk | [http://snyk.io](http://snyk.io)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| Oracle Critical Patch Update Advisory - April 2022 | [http://www.oracle.com](http://www.oracle.com)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| <span style="color: #ffffff">**No Description Provided**</span> | [http://snyk.io](http://snyk.io)<br><span style="color: #ffffff">**Inactive LinkNot Archived**</span> | ![URL Logo]() |
| Prototype Pollution in org.webjars:dojo | Snyk | [http://snyk.io](http://snyk.io)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| Prototype Pollution in org.webjars.npm:dojo | Snyk | [http://snyk.io](http://snyk.io)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| dojo/lang.js at 4c39c14349408fc8274e19b399ffc660512ed07c · dojo/dojo · GitHub | [http://github.com](http://github.com)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| Prototype Pollution in org.webjars.bower:dojo | Snyk | [http://snyk.io](http://snyk.io)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| Oracle Critical Patch Update Advisory - July 2022 | [http://www.oracle.com](http://www.oracle.com)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |