{
  "threat_severity" : "Moderate",
  "public_date" : "2020-06-13T00:00:00Z",
  "bugzilla" : {
    "description" : "dojo: Cross-site scripting vulnerability in the editor's LinkDialog plugin",
    "id" : "1879724",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1879724"
  },
  "cvss3" : {
    "cvss3_base_score" : "4.8",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
    "status" : "draft"
  },
  "cwe" : "CWE-79",
  "details" : [ "In Dijit before versions 1.11.11, and greater than or equal to 1.12.0 and less than 1.12.9, and greater than or equal to 1.13.0 and less than 1.13.8, and greater than or equal to 1.14.0 and less than 1.14.7, and greater than or equal to 1.15.0 and less than 1.15.4, and greater than or equal to 1.16.0 and less than 1.16.3, there is a cross-site scripting vulnerability in the Editor's LinkDialog plugin. This has been fixed in 1.11.11, 1.12.9, 1.13.8, 1.14.7, 1.15.4, 1.16.3.", "A flaw was found in dijit. A cross-site scripting vulnerability was identified in the Editor's LinkDialog plugin. The highest threat from this vulnerability is to data confidentiality and integrity." ],
  "statement" : "ipa as shipped with Red Hat Enterprise Linux 5, 6, 7, and 8 is not affected by this flaw because it does not use the dijit functionality of dojo.",
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Not affected",
    "package_name" : "ipa",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Not affected",
    "package_name" : "ipa",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "idm:client/ipa",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "idm:DL1/ipa",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2020-4051\nhttps://nvd.nist.gov/vuln/detail/CVE-2020-4051" ],
  "name" : "CVE-2020-4051",
  "csaw" : false
}