VulnerabilityModified
CVE-2019-11358
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution.
MEDIUM 6.1EPSS 87.2%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 87.2%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 87.22% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1321
- Affected
- jquery/jquery · debian/debian linux · drupal/drupal · backdropcms/backdrop · fedoraproject/fedora · opensuse/backports sle · opensuse/leap · netapp/oncommand system manager · netapp/snapcenter · redhat/cloudforms · redhat/virtualization manager · oracle/agile product lifecycle management for process · oracle/application express · oracle/application service level management · oracle/application testing suite · oracle/banking digital experience · oracle/banking enterprise collections · oracle/banking platform · oracle/bi publisher · oracle/big data discovery · +40 more
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00006.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00025.htmlMailing List, Third Party Advisory
- http://packetstormsecurity.com/files/152787/dotCMS-5.1.1-Vulnerable-Dependencies.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/153237/RetireJS-CORS-Issue-Script-Execution.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/156743/OctoberCMS-Insecure-Dependencies.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2019/May/10Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/May/11Mailing List, Patch, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/May/13Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2019/06/03/2Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/108023Broken Link, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHBA-2019:1570Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1456Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2587Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3023Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3024Third Party Advisory
- https://backdropcms.org/security/backdrop-sa-core-2019-009Third Party Advisory
- https://blog.jquery.com/2019/04/10/jquery-3-4-0-released/Release Notes, Vendor Advisory
- https://github.com/jquery/jquery/commit/753d591aea698e57d6db58c9f722cd0808619b1bPatch, Third Party Advisory
- https://github.com/jquery/jquery/pull/4333Patch, Third Party Advisory
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601Third Party Advisory
- https://lists.apache.org/thread.html/08720ef215ee7ab3386c05a1a90a7d1c852bf0706f176a7816bf65fc%40%3Ccommits.airflow.apache.org%3EIssue Tracking
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3EIssue Tracking
- https://lists.apache.org/thread.html/5928aa293e39d248266472210c50f176cac1535220f2486e6a7fa844%40%3Ccommits.airflow.apache.org%3EIssue Tracking
- https://lists.apache.org/thread.html/6097cdbd6f0a337bedd9bb5cc441b2d525ff002a96531de367e4259f%40%3Ccommits.airflow.apache.org%3EIssue Tracking
- https://lists.apache.org/thread.html/88fb0362fd40e5b605ea8149f63241537b8b6fb5bfa315391fc5cbb7%40%3Ccommits.airflow.apache.org%3EIssue Tracking
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3EIssue Tracking
- https://lists.apache.org/thread.html/b736d0784cf02f5a30fbb4c5902762a15ad6d47e17e2c5a17b7d6205%40%3Ccommits.airflow.apache.org%3EIssue Tracking
- https://lists.apache.org/thread.html/ba79cf1658741e9f146e4c59b50aee56656ea95d841d358d006c18b6%40%3Ccommits.roller.apache.org%3EIssue Tracking
- https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3EIssue Tracking
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3EIssue Tracking
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.