
DescriptionThe default configuration of the build process in Dojo 0.4.x before 0.4.4, 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 has the copyTests=true and mini=false options, which makes it easier for remote attackers to have an unspecified impact via a request to a (1) test or (2) demo component.
dojo (PTS)jessie, jessie (lts)1.10.2+dfsg-1+deb8u4fixed
buster (security)1.14.2+dfsg1-1+deb10u3fixed
sid, trixie, bookworm1.17.2+dfsg1-2.1fixed

dojosource(unstable)(not affected)


- dojo <not-affected> (Doesn't affect the Debian packaging)

