Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-11358

Опубликовано: 20 апр. 2019
Источник: debian
EPSS Низкий

Описание

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
drupal7removedpackage
jqueryfixed3.3.1~dfsg-2package
jqueryfixed3.1.1-2+deb9u1stretchpackage
node-jqueryfixed2.2.4+dfsg-4package
mediawikifixed1:1.31.2-1package
otrs2fixed6.0.26-1package
otrs2ignoredstretchpackage

Примечания

  • https://www.drupal.org/sa-core-2019-006

  • https://blog.jquery.com/2019/04/10/jquery-3-4-0-released/

  • https://github.com/DanielRuf/snyk-js-jquery-174006?files=1

  • https://snyk.io/vuln/SNYK-JS-JQUERY-174006

  • https://phabricator.wikimedia.org/T221739

  • https://lists.wikimedia.org/pipermail/wikitech-l/2019-June/092152.html

  • https://community.otrs.com/security-advisory-2020-05/

EPSS

Процентиль: 83%
0.02022
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 6 лет назад

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.

CVSS3: 5.6
redhat
около 6 лет назад

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.

CVSS3: 6.1
nvd
около 6 лет назад

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.

CVSS3: 6.1
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 6.1
github
около 6 лет назад

XSS in jQuery as used in Drupal, Backdrop CMS, and other products

EPSS

Процентиль: 83%
0.02022
Низкий