CVE-2019-11358

MEDIUMCVSS 6.1/10EPSS 87.22%

Last modified

CVE-2019-11358 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.. EPSS estimates a 87.22% chance of exploitation in the next 30 days.

Description

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.

Metrics

CVSS 3.1
6.1/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS Probability
87.22%

99.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
JqueryJquery< 3.4.0
DebianDebian Linux8.0
DebianDebian Linux9.0
DebianDebian Linux10.0
DrupalDrupal>= 7.0, < 7.66
DrupalDrupal>= 8.5.0, < 8.5.15
DrupalDrupal>= 8.6.0, < 8.6.15
BackdropcmsBackdrop>= 1.11.0, < 1.11.9
BackdropcmsBackdrop>= 1.12.0, < 1.12.6
FedoraprojectFedora28
FedoraprojectFedora29
FedoraprojectFedora30
OpensuseBackports Sle15.0Sp1
OpensuseLeap15.1
NetappOncommand System Manager>= 3.0, <= 3.1.3
NetappSnapcenterAll versions
RedhatCloudforms4.7
RedhatVirtualization Manager4.3
OracleAgile Product Lifecycle Management For Process6.1
OracleAgile Product Lifecycle Management For Process6.2.0.0
OracleAgile Product Lifecycle Management For Process6.2.1.0
OracleAgile Product Lifecycle Management For Process6.2.2.0
OracleAgile Product Lifecycle Management For Process6.2.3.0
OracleApplication Express< 19.1
OracleApplication Service Level Management13.2.0.0
OracleApplication Service Level Management13.3.0.0
OracleApplication Testing Suite12.5.0.3
OracleApplication Testing Suite13.1.0.1
OracleApplication Testing Suite13.2
OracleApplication Testing Suite13.2.0.1
OracleApplication Testing Suite13.3
OracleApplication Testing Suite13.3.0.1
OracleBanking Digital Experience18.1
OracleBanking Digital Experience18.2
OracleBanking Digital Experience18.3
OracleBanking Digital Experience19.1
OracleBanking Digital Experience19.2
OracleBanking Digital Experience20.1
OracleBanking Enterprise Collections>= 2.7.0, <= 2.8.0
OracleBanking Platform>= 2.4.0, <= 2.10.0
OracleBi Publisher5.5.0.0.0
OracleBi Publisher12.2.1.3.0
OracleBi Publisher12.2.1.4.0
OracleBig Data Discovery1.6
OracleBusiness Process Management Suite12.2.1.3.0
OracleBusiness Process Management Suite12.2.1.4.0
OracleCommunications Analytics12.1.1
OracleCommunications Application Session Controller3.8m0
OracleCommunications Billing And Revenue Management7.5
OracleCommunications Billing And Revenue Management7.5.0.23.0

Showing 50 of 218 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-11358?
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
How severe is CVE-2019-11358?
CVE-2019-11358 has a CVSS score of 6.1/10 (MEDIUM severity). The EPSS model estimates a 87.22% probability of exploitation in the next 30 days.
How do I fix CVE-2019-11358?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-11358?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST