CVE-2019-11358
published 2019-04-20CVE-2019-11358: jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an…
medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
ITWEXPLOIT
Exploited in the wild
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
Affected
247 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| backdropcms | backdrop | >= 1.11.0 < 1.11.9 | 1.11.9 |
| backdropcms | backdrop | >= 1.12.0 < 1.12.6 | 1.12.6 |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | mediawiki | < mediawiki 1:1.31.2-1 (bookworm) | mediawiki 1:1.31.2-1 (bookworm) |
| debian | node-jquery | < mediawiki 1:1.31.2-1 (bookworm) | mediawiki 1:1.31.2-1 (bookworm) |
| debian | otrs2 | < mediawiki 1:1.31.2-1 (bookworm) | mediawiki 1:1.31.2-1 (bookworm) |
| djangoproject | django | >= 2.0a1 < 2.1.9 | 2.1.9 |
| djangoproject | django | >= 2.2a1 < 2.2.2 | 2.2.2 |
| drupal | core | >= 8.0.0 < 8.5.15 | 8.5.15 |
| drupal | core | >= 8.6.0 < 8.6.15 | 8.6.15 |
| drupal | drupal | >= 7.0 < 7.66 | 7.66 |
| drupal | drupal | >= 8.5.0 < 8.5.15 | 8.5.15 |
| drupal | drupal | >= 8.6.0 < 8.6.15 | 8.6.15 |
| drupal | drupal_core | — | — |
| ezsystems | ezplatform-admin-ui-assets | >= 4.0.0 < 4.2.0 | 4.2.0 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| joomla | joomla_! | 3.0.0 – 3.9.4 | — |
| jquery | jquery | < 3.4.0 | 3.4.0 |
| jquery | jquery | >= 0 < 1.7.2+dfsg-2ubuntu1+esm1 | 1.7.2+dfsg-2ubuntu1+esm1 |
| jquery | jquery | >= 0 < 1.11.3+dfsg-4ubuntu0.1~esm1 | 1.11.3+dfsg-4ubuntu0.1~esm1 |
| jquery | jquery | >= 0 < 3.2.1-1ubuntu0.1~esm1 | 3.2.1-1ubuntu0.1~esm1 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
ghsa6.1MEDIUM
osv6.1MEDIUM
vulncheck6.1MEDIUM