CVE-2019-11358
medium · 6.1jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
6.1
CVSS
87.2%
EPSS (exploit prob.)
100th
EPSS percentile
2019-04-20
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses
CWE-1321
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| jquery | jquery | < 3.4.0 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| drupal | drupal | >= 7.0, < 7.66 |
| drupal | drupal | >= 8.5.0, < 8.5.15 |
| drupal | drupal | >= 8.6.0, < 8.6.15 |
| backdropcms | backdrop | >= 1.11.0, < 1.11.9 |
| backdropcms | backdrop | >= 1.12.0, < 1.12.6 |
| fedoraproject | fedora | 28 |
| fedoraproject | fedora | 29 |
| fedoraproject | fedora | 30 |
| opensuse | backports_sle | 15.0 |
| opensuse | leap | 15.1 |
| netapp | oncommand_system_manager | >= 3.0, <= 3.1.3 |
| netapp | snapcenter | all versions |
| redhat | cloudforms | 4.7 |
| redhat | virtualization_manager | 4.3 |
| oracle | agile_product_lifecycle_management_for_process | 6.1 |
| oracle | agile_product_lifecycle_management_for_process | 6.2.0.0 |
| oracle | agile_product_lifecycle_management_for_process | 6.2.1.0 |
| oracle | agile_product_lifecycle_management_for_process | 6.2.2.0 |
| oracle | agile_product_lifecycle_management_for_process | 6.2.3.0 |
| oracle | application_express | < 19.1 |
| oracle | application_service_level_management | 13.2.0.0 |
| oracle | application_service_level_management | 13.3.0.0 |
| oracle | application_testing_suite | 12.5.0.3 |
| oracle | application_testing_suite | 13.1.0.1 |
| oracle | application_testing_suite | 13.2 |
| oracle | application_testing_suite | 13.2.0.1 |
| oracle | application_testing_suite | 13.3 |
| oracle | application_testing_suite | 13.3.0.1 |
| oracle | banking_digital_experience | 18.1 |
| oracle | banking_digital_experience | 18.2 |
| oracle | banking_digital_experience | 18.3 |
| oracle | banking_digital_experience | 19.1 |
| oracle | banking_digital_experience | 19.2 |
| oracle | banking_digital_experience | 20.1 |
| oracle | banking_enterprise_collections | >= 2.7.0, <= 2.8.0 |
| oracle | banking_platform | >= 2.4.0, <= 2.10.0 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00025.html
- http://packetstormsecurity.com/files/152787/dotCMS-5.1.1-Vulnerable-Dependencies.html
- http://packetstormsecurity.com/files/153237/RetireJS-CORS-Issue-Script-Execution.html
- http://packetstormsecurity.com/files/156743/OctoberCMS-Insecure-Dependencies.html
- http://seclists.org/fulldisclosure/2019/May/10
- http://seclists.org/fulldisclosure/2019/May/11
- http://seclists.org/fulldisclosure/2019/May/13
- http://www.openwall.com/lists/oss-security/2019/06/03/2
- http://www.securityfocus.com/bid/108023
- https://access.redhat.com/errata/RHBA-2019:1570
- https://access.redhat.com/errata/RHSA-2019:1456
- https://access.redhat.com/errata/RHSA-2019:2587
- https://access.redhat.com/errata/RHSA-2019:3023
- https://access.redhat.com/errata/RHSA-2019:3024
- https://backdropcms.org/security/backdrop-sa-core-2019-009
- https://blog.jquery.com/2019/04/10/jquery-3-4-0-released/
- https://github.com/jquery/jquery/commit/753d591aea698e57d6db58c9f722cd0808619b1b
- https://github.com/jquery/jquery/pull/4333
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601
- https://lists.apache.org/thread.html/08720ef215ee7ab3386c05a1a90a7d1c852bf0706f176a7816bf65fc%40%3Ccommits.airflow.apache.org%3E
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
- https://lists.apache.org/thread.html/5928aa293e39d248266472210c50f176cac1535220f2486e6a7fa844%40%3Ccommits.airflow.apache.org%3E
- https://lists.apache.org/thread.html/6097cdbd6f0a337bedd9bb5cc441b2d525ff002a96531de367e4259f%40%3Ccommits.airflow.apache.org%3E
- https://lists.apache.org/thread.html/88fb0362fd40e5b605ea8149f63241537b8b6fb5bfa315391fc5cbb7%40%3Ccommits.airflow.apache.org%3E
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2019-11358