SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-11358

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution.

MEDIUM 6.1EPSS 87.2%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 87.2%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
87.22% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-1321
Affected
jquery/jquery · debian/debian linux · drupal/drupal · backdropcms/backdrop · fedoraproject/fedora · opensuse/backports sle · opensuse/leap · netapp/oncommand system manager · netapp/snapcenter · redhat/cloudforms · redhat/virtualization manager · oracle/agile product lifecycle management for process · oracle/application express · oracle/application service level management · oracle/application testing suite · oracle/banking digital experience · oracle/banking enterprise collections · oracle/banking platform · oracle/bi publisher · oracle/big data discovery · +40 more
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.