← All CVEs

CVE-2019-11358

medium · 6.1

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.

6.1
CVSS
87.2%
EPSS (exploit prob.)
100th
EPSS percentile
2019-04-20
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Weaknesses

CWE-1321

Affected products

VendorProductAffected versions
jqueryjquery< 3.4.0
debiandebian_linux8.0
debiandebian_linux9.0
debiandebian_linux10.0
drupaldrupal>= 7.0, < 7.66
drupaldrupal>= 8.5.0, < 8.5.15
drupaldrupal>= 8.6.0, < 8.6.15
backdropcmsbackdrop>= 1.11.0, < 1.11.9
backdropcmsbackdrop>= 1.12.0, < 1.12.6
fedoraprojectfedora28
fedoraprojectfedora29
fedoraprojectfedora30
opensusebackports_sle15.0
opensuseleap15.1
netapponcommand_system_manager>= 3.0, <= 3.1.3
netappsnapcenterall versions
redhatcloudforms4.7
redhatvirtualization_manager4.3
oracleagile_product_lifecycle_management_for_process6.1
oracleagile_product_lifecycle_management_for_process6.2.0.0
oracleagile_product_lifecycle_management_for_process6.2.1.0
oracleagile_product_lifecycle_management_for_process6.2.2.0
oracleagile_product_lifecycle_management_for_process6.2.3.0
oracleapplication_express< 19.1
oracleapplication_service_level_management13.2.0.0
oracleapplication_service_level_management13.3.0.0
oracleapplication_testing_suite12.5.0.3
oracleapplication_testing_suite13.1.0.1
oracleapplication_testing_suite13.2
oracleapplication_testing_suite13.2.0.1
oracleapplication_testing_suite13.3
oracleapplication_testing_suite13.3.0.1
oraclebanking_digital_experience18.1
oraclebanking_digital_experience18.2
oraclebanking_digital_experience18.3
oraclebanking_digital_experience19.1
oraclebanking_digital_experience19.2
oraclebanking_digital_experience20.1
oraclebanking_enterprise_collections>= 2.7.0, <= 2.8.0
oraclebanking_platform>= 2.4.0, <= 2.10.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-11358