# Fix for CVE-2021-23450

**URL:** <https://discourse.dojo.io/t/fix-for-cve-2021-23450/589>\
**Category:** Dojo 1.x users\
**Created:** [January 6, 2022, 8:33pm UTC](https://discourse.dojo.io/t/fix-for-cve-2021-23450/589 "2022-01-06T20:33:32Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![asrdojo](https://avatars.discourse-cdn.com/v4/letter/a/b4bc9f/32.png) [@asrdojo](https://discourse.dojo.io/u/asrdojo)\
**Post date:** [January 6, 2022, 8:33pm UTC](https://discourse.dojo.io/t/fix-for-cve-2021-23450/589/1 "2022-01-06T20:33:32Z")

</div>

Hello, Will there be a fix released for the following? Any mitigations?

> **[GitHub - dojo/dojo: Dojo 1 - the Dojo 1 toolkit core library.](https://github.com/dojo/dojo)**
>
> Dojo 1 - the Dojo 1 toolkit core library. Contribute to dojo/dojo development by creating an account on GitHub.

> **[Prototype Pollution in dojo | CVE-2021-23450 | Snyk](https://security.snyk.io/vuln/SNYK-JS-DOJO-1535223)**
>
> Snyk Vulnerability Database

CVEs: (details as of the time of ADV creation)  
CVEID: CVE-2021-23450  
Description: All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.  
CVSS Base Score: 9.8
