← Back

CVE-2019-11358

nvd nist
Published: Apr 20, 2019Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.

Affected (218)

Products: Jquery: Jquery · Debian: Debian Linux · Drupal: Drupal · +8 more
Show all products
Jquery: Jquery · Debian: Debian Linux · Drupal: Drupal · Backdropcms: Backdrop · Fedoraproject: Fedora · Opensuse: Backports Sle, Leap · Netapp: Oncommand System Manager, Snapcenter · Redhat: Cloudforms, Virtualization Manager · Oracle: Agile Product Lifecycle Management For Process, Application Express, Application Service Level Management, Application Testing Suite, Banking Digital Experience, Banking Enterprise Collections, Banking Platform, Bi Publisher, Big Data Discovery, Business Process Management Suite, Communications Analytics, Communications Application Session Controller, Communications Billing And Revenue Management, Communications Diameter Signaling Router, Communications Eagle Application Processor, Communications Element Manager, Communications Interactive Session Recorder, Communications Operations Monitor, Communications Services Gatekeeper, Communications Session Report Manager, Communications Session Route Manager, Communications Unified Inventory Management, Communications Webrtc Session Controller, Diagnostic Assistant, Enterprise Manager Ops Center, Enterprise Session Border Controller, Financial Services Analytical Applications Infrastructure, Financial Services Analytical Applications Reconciliation Framework, Financial Services Asset Liability Management, Financial Services Balance Sheet Planning, Financial Services Basel Regulatory Capital Basic, Financial Services Basel Regulatory Capital Internal Ratings Based Approach, Financial Services Data Foundation, Financial Services Data Governance For Us Regulatory Reporting, Financial Services Data Integration Hub, Financial Services Enterprise Financial Performance Analytics, Financial Services Funds Transfer Pricing, Financial Services Hedge Management And Ifrs Valuations, Financial Services Institutional Performance Analytics, Financial Services Liquidity Risk Management, Financial Services Liquidity Risk Measurement And Management, Financial Services Loan Loss Forecasting And Provisioning, Financial Services Market Risk Measurement And Management, Financial Services Price Creation And Discovery, Financial Services Profitability Management, Financial Services Regulatory Reporting For De Nederlandsche Bank, Financial Services Regulatory Reporting For European Banking Authority, Financial Services Regulatory Reporting For Us Federal Reserve, Financial Services Retail Customer Analytics, Financial Services Retail Performance Analytics, Financial Services Revenue Management And Billing, Fusion Middleware Mapviewer, Healthcare Foundation, Healthcare Translational Research, Hospitality Guest Access, Hospitality Materials Control, Hospitality Simphony, Identity Manager, Insurance Accounting Analyzer, Insurance Allocation Manager For Enterprise Profitability, Insurance Data Foundation, Insurance Ifrs 17 Analyzer, Insurance Insbridge Rating And Underwriting, Insurance Performance Insight, Jd Edwards Enterpriseone Tools, Jdeveloper, Jdeveloper And Adf, Knowledge, Peoplesoft Enterprise Peopletools, Policy Automation, Policy Automation Connector For Siebel, Policy Automation For Mobile Devices, Primavera Gateway, Primavera Unifier, Real Time Scheduler, Rest Data Services, Retail Back Office, Retail Central Office, Retail Customer Insights, Retail Customer Management And Segmentation Foundation, Retail Point Of Service, Retail Returns Management, Service Bus, Siebel Mobile Applications, Siebel Ui Framework, Storagetek Tape Analytics Sw Tool, System Utilities, Tape Library Acsls, Transportation Management, Utilities Mobile Workforce Management, Webcenter Sites, Weblogic Server · Joomla: Joomla! · Juniper: Junos
1 product
Jquery
1 product
Debian Linux
1 product
Drupal
1 product
Backdrop
1 product
Fedora
2 products
Backports Sle
Leap
2 products
Oncommand System Manager
Snapcenter
2 products
Cloudforms
Virtualization Manager
92 products
Application Express
Application Testing Suite
Banking Digital Experience
Banking Enterprise Collections
Banking Platform
Bi Publisher
Big Data Discovery
Business Process Management Suite
Communications Analytics
Communications Element Manager
Communications Operations Monitor
Diagnostic Assistant
Enterprise Manager Ops Center
Fusion Middleware Mapviewer
Healthcare Foundation
Healthcare Translational Research
Hospitality Guest Access
Hospitality Materials Control
Hospitality Simphony
Identity Manager
Insurance Accounting Analyzer
Insurance Data Foundation
Insurance Ifrs 17 Analyzer
Insurance Performance Insight
Jd Edwards Enterpriseone Tools
Jdeveloper
Jdeveloper And Adf
Knowledge
Peoplesoft Enterprise Peopletools
Policy Automation
Primavera Gateway
Primavera Unifier
Real Time Scheduler
Rest Data Services
Retail Back Office
Retail Central Office
Retail Customer Insights
Retail Point Of Service
Retail Returns Management
Service Bus
Siebel Mobile Applications
Siebel Ui Framework
Storagetek Tape Analytics Sw Tool
System Utilities
Tape Library Acsls
Transportation Management
Webcenter Sites
Weblogic Server
1 product
Joomla!
1 product
Junos
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.4.0
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 8.0
Version 9.0
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Drupal
From 7.0 to 7.66
From 8.5.0 to 8.5.15
From 8.6.0 to 8.6.15
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Backdropcms
From 1.11.0 to 1.11.9
From 1.12.0 to 1.12.6
Configuration E
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 28
Version 29
Version 30
Configuration F
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 15.0 sp1
Version 15.1
Configuration G
2 vulnerable
Vulnerable SoftwareAffected Versions
From 3.0 to 3.1.3
All versions
Configuration H
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 4.7
Version 4.3
Configuration I
198 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 6.1
Version 6.2.0.0
Version 6.2.1.0
Version 6.2.2.0
Version 6.2.3.0
Before 19.1
Oracle
Version 13.2.0.0
Version 13.3.0.0
Oracle
Version 12.5.0.3
Version 13.1.0.1
Version 13.2.0.1
Version 13.2
Version 13.3.0.1
Version 13.3
Oracle
Version 18.1
Version 18.2
Version 18.3
Version 19.1
Version 19.2
Version 20.1
From 2.7.0 to 2.8.0
From 2.4.0 to 2.10.0
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 5.5.0.0.0
Version 1.6
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 12.1.1
Version 3.8m0
Oracle
Version 12.0.0.3.0
Version 12.0
Version 7.5.0.23.0
Version 7.5
Oracle
Version 8.0.0
Version 8.1
Version 8.2.1
Version 8.2
From 16.1.0 to 16.4.0
Oracle
Version 8.1.1
Version 8.2.0
Version 8.2.1
From 6.0 to 6.4
Oracle
From 4.1 to 4.3
Version 3.4
Version 4.0
Version 4.1.0
Version 7.0
Oracle
Version 8.1.1
Version 8.2.0
Version 8.2.1
Oracle
Version 8.1.1
Version 8.2.0
Version 8.2.1
Oracle
Version 7.3
Version 7.4.0
Version 7.2
Version 2.12.36
Oracle
Version 12.3.3
Version 12.4.0.0
Version 12.4.0
Version 8.4
Oracle
From 7.3.3 to 7.3.5
From 8.0.2 to 8.1.0
Oracle
From 8.0.4 to 8.0.7
Version 8.1.0
Oracle
From 8.0.4 to 8.0.7
Version 8.1.0
Version 8.0.8
Oracle
From 8.0.4 to 8.0.7
Version 8.1.0
Oracle
From 8.0.4 to 8.0.7
Version 8.1.0
From 8.0.4 to 8.0.8
From 8.0.6 to 8.0.9
Oracle
From 8.0.5 to 8.0.7
Version 8.1.0
Oracle
Version 8.0.6
Version 8.0.7
Oracle
From 8.0.4 to 8.0.7
Version 8.1.0
Oracle
From 8.0.4 to 8.0.7
Version 8.1.0
Oracle
From 8.0.4 to 8.0.7
Version 8.1.0
Oracle
Version 8.0.0.1.0
Version 8.0.2
Version 8.0.4.0.0
Version 8.0.5.0.0
Version 8.0.6
Oracle
Version 8.0.7
Version 8.0.8
Version 8.1.0
Oracle
From 8.0.2 to 8.0.7
Version 8.1.0
Oracle
Version 8.0.5
Version 8.0.6
Version 8.0.8
From 8.0.4 to 8.0.7
Oracle
From 8.0.4 to 8.0.7
Version 8.1.0
Version 8.0.4
Oracle
Version 8.0.6
Version 8.0.7
From 8.0.4 to 8.0.7
From 8.0.4 to 8.0.6
Oracle
Version 8.0.6
Version 8.0.7
Oracle
Version 2.4.0.0
Version 2.4.0.1
Version 12.2.1.3.0
Oracle
Version 7.1.1
Version 7.2.0
Version 7.2.2
Version 7.3.0
Oracle
Version 3.1.0
Version 3.2.1
Version 3.3.1
Version 3.3.2
Version 3.4.0
Oracle
Version 4.2.0
Version 4.2.1
Version 18.1
Oracle
From 19.1.0 to 19.1.2
Version 18.1
Version 18.2
Version 12.2.1.3.0
Version 8.0.9
Oracle
Version 8.0.8
Version 8.1.0
From 8.0.4 to 8.0.7
Oracle
Version 8.0.6
Version 8.0.7
Oracle
From 5.0.0.0 to 5.6.0.0
Version 5.6.1.0
Version 8.0.7
Version 9.2
Oracle
Version 11.1.1.9.0
Version 12.2.1.3.0
Version 12.2.1.4.0
Oracle
Version 11.1.1.9.0
Version 12.1.3.0.0
Version 12.2.1.3.0
From 8.6.0 to 8.6.3
Oracle
Version 8.55
Version 8.56
Version 8.57
Version 8.58
Oracle
From 12.2.0 to 12.2.15
Version 10.4.7
Version 12.1.0
Version 12.1.1
Version 10.4.6
From 12.2.0 to 12.2.15
Oracle
From 16.2.0 to 16.2.11
From 17.12.0 to 17.12.7
From 18.8.0 to 18.8.9
From 19.12.0 to 19.12.4
Version 15.2.18
Oracle
From 17.7 to 17.12
Version 16.1
Version 16.2
Version 18.8
From 2.3.0.1 to 2.3.0.3
Oracle
Version 11.2.0.4
Version 12.1.0.2
Version 12.2.0.1
Version 18c
Version 19c
Oracle
Version 14.0
Version 14.1
Oracle
Version 14.0
Version 14.1
Oracle
Version 15.0
Version 16.0
Oracle
Version 18.0
Version 19.0
Oracle
Version 14.0
Version 14.1
Oracle
Version 14.0
Version 14.1
Oracle
Version 11.1.1.9.0
Version 12.1.3.0.0
Version 12.2.1.3.0
Up to 19.8
Version 20.8
Version 2.3.0
Version 19.1
Oracle
Version 8.5.1
Version 8.5
Version 1.4.3
From 2.3.0.1 to 2.3.0.3
Version 12.2.1.3.0
Oracle
Version 10.3.6.0.0
Version 12.1.3.0.0
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 14.1.1.0.0
Configuration J
1 vulnerable
Vulnerable SoftwareAffected Versions
From 3.0.0 to 3.9.4
Configuration K
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 21.2

References (146)

Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListPatchThird Party Advisory
Source: cve@mitre.org
Mailing ListPatchThird Party Advisory
Source: cve@mitre.org
Mailing ListPatchThird Party Advisory
Source: cve@mitre.org
Broken LinkThird Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Release NotesVendor Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Issue TrackingMailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListPatchThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
ExploitThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.