CVE-2019-11358 - CVE House
Back to Database
Status published Medium CVE-2019-11358

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and...

Vulnerability Description

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-11358

Credits & Attribution

No credits recorded in the NVD database.

References

Affected Vendor

Affected Software

jquery, debian linux, drupal, backdrop, fedora, backports sle, leap, oncommand system manager, snapcenter, cloudforms, virtualization manager, agile product lifecycle management for process, application express, application service level management, application testing suite, banking digital experience, banking enterprise collections, banking platform, bi publisher, big data discovery, business process management suite, communications analytics, communications application session controller, communications billing and revenue management, communications diameter signaling router, communications eagle application processor, communications element manager, communications interactive session recorder, communications operations monitor, communications services gatekeeper, communications session report manager, communications session route manager, communications unified inventory management, communications webrtc session controller, diagnostic assistant, enterprise manager ops center, enterprise session border controller, financial services analytical applications infrastructure, financial services analytical applications reconciliation framework, financial services asset liability management, financial services balance sheet planning, financial services basel regulatory capital basic, financial services basel regulatory capital internal ratings based approach, financial services data foundation, financial services data governance for us regulatory reporting, financial services data integration hub, financial services enterprise financial performance analytics, financial services funds transfer pricing, financial services hedge management and ifrs valuations, financial services institutional performance analytics, financial services liquidity risk management, financial services liquidity risk measurement and management, financial services loan loss forecasting and provisioning, financial services market risk measurement and management, financial services price creation and discovery, financial services profitability management, financial services regulatory reporting for de nederlandsche bank, financial services regulatory reporting for european banking authority, financial services regulatory reporting for us federal reserve, financial services retail customer analytics, financial services retail performance analytics, financial services revenue management and billing, fusion middleware mapviewer, healthcare foundation, healthcare translational research, hospitality guest access, hospitality materials control, hospitality simphony, identity manager, insurance accounting analyzer, insurance allocation manager for enterprise profitability, insurance data foundation, insurance ifrs 17 analyzer, insurance insbridge rating and underwriting, insurance performance insight, jd edwards enterpriseone tools, jdeveloper, jdeveloper and adf, knowledge, peoplesoft enterprise peopletools, policy automation, policy automation connector for siebel, policy automation for mobile devices, primavera gateway, primavera unifier, real-time scheduler, rest data services, retail back office, retail central office, retail customer insights, retail customer management and segmentation foundation, retail point-of-service, retail returns management, service bus, siebel mobile applications, siebel ui framework, storagetek tape analytics sw tool, system utilities, tape library acsls, transportation management, utilities mobile workforce management, webcenter sites, weblogic server, joomla\!, junos
Vulnerable Versions:
0, 8.0, 9.0, 10.0, 7.0, 8.5.0, 8.6.0, 1.11.0, 1.12.0, 28, 29, 30, 15.0, 15.1, 3.0, 4.7, 4.3, 6.1, 6.2.0.0, 6.2.1.0, 6.2.2.0, 6.2.3.0, 13.2.0.0, 13.3.0.0, 12.5.0.3, 13.1.0.1, 13.2, 13.2.0.1, 13.3, 13.3.0.1, 18.1, 18.2, 18.3, 19.1, 19.2, 20.1, 2.7.0, 2.4.0, 5.5.0.0.0, 12.2.1.3.0, 12.2.1.4.0, 1.6, 12.1.1, 3.8m0, 7.5, 7.5.0.23.0, 12.0, 12.0.0.3.0, 8.0.0, 8.1, 8.2, 8.2.1, 16.1.0, 8.1.1, 8.2.0, 6.0, 4.1, 3.4, 4.0, 4.1.0, 7.3, 7.4.0, 7.2, 2.12.36, 12.3.3, 12.4.0, 12.4.0.0, 8.4, 7.3.3, 8.0.2, 8.0.4, 8.1.0, 8.0.8, 8.0.6, 8.0.5, 8.0.7, 8.0.0.1.0, 8.0.4.0.0, 8.0.5.0.0, 2.4.0.0, 2.4.0.1, 7.1.1, 7.2.0, 7.2.2, 7.3.0, 3.1.0, 3.2.1, 3.3.1, 3.3.2, 3.4.0, 4.2.0, 4.2.1, 19.1.0, 8.0.9, 5.0.0.0, 5.6.1.0, 9.2, 11.1.1.9.0, 12.1.3.0.0, 8.55, 8.56, 8.57, 8.58, 12.2.0, 10.4.7, 12.1.0, 10.4.6, 16.2.0, 17.12.0, 18.8.0, 19.12.0, 15.2.18, 17.7, 16.1, 16.2, 18.8, 2.3.0.1, 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c, 19c, 14.0, 14.1, 16.0, 18.0, 19.0, 20.8, 2.3.0, 8.5, 8.5.1, 1.4.3, 10.3.6.0.0, 14.1.1.0.0, 3.0.0, 21.2

Timeline

Official Publish: April 19th, 2019
Last Modified: November 15th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.