Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-11358

Опубликовано: 27 мар. 2019
Источник: redhat
CVSS3: 5.6
EPSS Низкий

Описание

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable proto property, it could extend the native Object.prototype.

A Prototype Pollution vulnerability was found in jquery. Untrusted JSON passed to the extend function could lead to modifying objects up the prototype chain, including the global Object. A crafted JSON object passed to a vulnerable method could lead to denial of service or data injection, with various consequences.

Отчет

Red Hat Virtualization 4.2 EUS contains the affected version of bootstrap in the packages ovirt-js-dependencies and ovirt-engine-dashboard. These packages are deprecated in Red Hat Virtualization 4.3.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 2jqueryWill not fix
Red Hat Enterprise Linux 6ipaWill not fix
Red Hat Enterprise Linux 6pcpWill not fix
Red Hat Enterprise Linux 6python-coverageWill not fix
Red Hat Enterprise Linux 6python-weberrorWill not fix
Red Hat Enterprise Linux 7ipsilonWill not fix
Red Hat Enterprise Linux 7pcpWill not fix
Red Hat Enterprise Linux 7pki-coreWill not fix
Red Hat Enterprise Linux 7publicanWill not fix
Red Hat Enterprise Linux 7python-coverageWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1701972jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection

EPSS

Процентиль: 84%
0.02394
Низкий

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 6 лет назад

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.

CVSS3: 6.1
nvd
больше 6 лет назад

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.

CVSS3: 6.1
msrc
11 месяцев назад

Описание отсутствует

CVSS3: 6.1
debian
больше 6 лет назад

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other produc ...

CVSS3: 6.1
github
больше 6 лет назад

XSS in jQuery as used in Drupal, Backdrop CMS, and other products

EPSS

Процентиль: 84%
0.02394
Низкий

5.6 Medium

CVSS3