Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-11358

Опубликовано: 27 мар. 2019
Источник: redhat
CVSS3: 5.6
EPSS Низкий

Описание

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable proto property, it could extend the native Object.prototype.

A Prototype Pollution vulnerability was found in jquery. Untrusted JSON passed to the extend function could lead to modifying objects up the prototype chain, including the global Object. A crafted JSON object passed to a vulnerable method could lead to denial of service or data injection, with various consequences.

Отчет

Red Hat Virtualization 4.2 EUS contains the affected version of bootstrap in the packages ovirt-js-dependencies and ovirt-engine-dashboard. These packages are deprecated in Red Hat Virtualization 4.3.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5jquery-rjsNot affected
Red Hat 3scale API Management Platform 2jqueryWill not fix
Red Hat Enterprise Linux 6ipaWill not fix
Red Hat Enterprise Linux 6pcpWill not fix
Red Hat Enterprise Linux 6python-coverageWill not fix
Red Hat Enterprise Linux 6python-weberrorWill not fix
Red Hat Enterprise Linux 7ipsilonWill not fix
Red Hat Enterprise Linux 7pcpWill not fix
Red Hat Enterprise Linux 7pki-coreWill not fix
Red Hat Enterprise Linux 7publicanWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1701972jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection

EPSS

Процентиль: 83%
0.02022
Низкий

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 6 лет назад

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.

CVSS3: 6.1
nvd
около 6 лет назад

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.

CVSS3: 6.1
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 6.1
debian
около 6 лет назад

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other produc ...

CVSS3: 6.1
github
около 6 лет назад

XSS in jQuery as used in Drupal, Backdrop CMS, and other products

EPSS

Процентиль: 83%
0.02022
Низкий

5.6 Medium

CVSS3