CVE-2019-11358
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD
Description
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
Affected (218)
Show all products
Jquery: Jquery · Debian: Debian Linux · Drupal: Drupal · Backdropcms: Backdrop · Fedoraproject: Fedora · Opensuse: Backports Sle, Leap · Netapp: Oncommand System Manager, Snapcenter · Redhat: Cloudforms, Virtualization Manager · Oracle: Agile Product Lifecycle Management For Process, Application Express, Application Service Level Management, Application Testing Suite, Banking Digital Experience, Banking Enterprise Collections, Banking Platform, Bi Publisher, Big Data Discovery, Business Process Management Suite, Communications Analytics, Communications Application Session Controller, Communications Billing And Revenue Management, Communications Diameter Signaling Router, Communications Eagle Application Processor, Communications Element Manager, Communications Interactive Session Recorder, Communications Operations Monitor, Communications Services Gatekeeper, Communications Session Report Manager, Communications Session Route Manager, Communications Unified Inventory Management, Communications Webrtc Session Controller, Diagnostic Assistant, Enterprise Manager Ops Center, Enterprise Session Border Controller, Financial Services Analytical Applications Infrastructure, Financial Services Analytical Applications Reconciliation Framework, Financial Services Asset Liability Management, Financial Services Balance Sheet Planning, Financial Services Basel Regulatory Capital Basic, Financial Services Basel Regulatory Capital Internal Ratings Based Approach, Financial Services Data Foundation, Financial Services Data Governance For Us Regulatory Reporting, Financial Services Data Integration Hub, Financial Services Enterprise Financial Performance Analytics, Financial Services Funds Transfer Pricing, Financial Services Hedge Management And Ifrs Valuations, Financial Services Institutional Performance Analytics, Financial Services Liquidity Risk Management, Financial Services Liquidity Risk Measurement And Management, Financial Services Loan Loss Forecasting And Provisioning, Financial Services Market Risk Measurement And Management, Financial Services Price Creation And Discovery, Financial Services Profitability Management, Financial Services Regulatory Reporting For De Nederlandsche Bank, Financial Services Regulatory Reporting For European Banking Authority, Financial Services Regulatory Reporting For Us Federal Reserve, Financial Services Retail Customer Analytics, Financial Services Retail Performance Analytics, Financial Services Revenue Management And Billing, Fusion Middleware Mapviewer, Healthcare Foundation, Healthcare Translational Research, Hospitality Guest Access, Hospitality Materials Control, Hospitality Simphony, Identity Manager, Insurance Accounting Analyzer, Insurance Allocation Manager For Enterprise Profitability, Insurance Data Foundation, Insurance Ifrs 17 Analyzer, Insurance Insbridge Rating And Underwriting, Insurance Performance Insight, Jd Edwards Enterpriseone Tools, Jdeveloper, Jdeveloper And Adf, Knowledge, Peoplesoft Enterprise Peopletools, Policy Automation, Policy Automation Connector For Siebel, Policy Automation For Mobile Devices, Primavera Gateway, Primavera Unifier, Real Time Scheduler, Rest Data Services, Retail Back Office, Retail Central Office, Retail Customer Insights, Retail Customer Management And Segmentation Foundation, Retail Point Of Service, Retail Returns Management, Service Bus, Siebel Mobile Applications, Siebel Ui Framework, Storagetek Tape Analytics Sw Tool, System Utilities, Tape Library Acsls, Transportation Management, Utilities Mobile Workforce Management, Webcenter Sites, Weblogic Server · Joomla: Joomla! · Juniper: Junos
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.11.0 to 1.11.9 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 28 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 15.0 sp1 | |
| Version 15.1 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0 to 3.1.3 | |
| All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.7 | |
| Version 4.3 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.1 | |
| Before 19.1 | |
| Version 13.2.0.0 | |
| Version 12.5.0.3 | |
| Version 18.1 | |
| From 2.7.0 to 2.8.0 | |
| From 2.4.0 to 2.10.0 | |
| Version 12.2.1.3.0 | |
| Version 1.6 | |
| Version 12.2.1.3.0 | |
| Version 12.1.1 | |
| Version 3.8m0 | |
| Version 12.0.0.3.0 | |
| Version 8.0.0 | |
| From 16.1.0 to 16.4.0 | |
| Version 8.1.1 | |
| From 6.0 to 6.4 | |
| From 4.1 to 4.3 | |
| Version 7.0 | |
| Version 8.1.1 | |
| Version 8.1.1 | |
| Version 7.3 | |
| Version 7.2 | |
| Version 2.12.36 | |
| Version 12.3.3 | |
| Version 8.4 | |
| From 7.3.3 to 7.3.5 | |
| From 8.0.4 to 8.0.7 | |
| From 8.0.4 to 8.0.7 | |
| Version 8.0.8 | |
| From 8.0.4 to 8.0.7 | |
| From 8.0.4 to 8.0.7 | |
| From 8.0.4 to 8.0.8 | |
| From 8.0.6 to 8.0.9 | |
| From 8.0.5 to 8.0.7 | |
| Version 8.0.6 | |
| From 8.0.4 to 8.0.7 | |
| From 8.0.4 to 8.0.7 | |
| From 8.0.4 to 8.0.7 | |
| Version 8.0.0.1.0 | |
| Version 8.0.7 | |
| From 8.0.2 to 8.0.7 | |
| Version 8.0.5 | |
| From 8.0.4 to 8.0.7 | |
| From 8.0.4 to 8.0.7 | |
| Version 8.0.4 | |
| Version 8.0.6 | |
| From 8.0.4 to 8.0.7 | |
| From 8.0.4 to 8.0.6 | |
| Version 8.0.6 | |
| Version 2.4.0.0 | |
| Version 12.2.1.3.0 | |
| Version 7.1.1 | |
| Version 3.1.0 | |
| Version 4.2.0 | |
| Version 18.1 | |
| From 19.1.0 to 19.1.2 | |
| Version 12.2.1.3.0 | |
| Version 8.0.9 | |
| Version 8.0.8 | |
| From 8.0.4 to 8.0.7 | |
| Version 8.0.6 | |
| From 5.0.0.0 to 5.6.0.0 | |
| Version 8.0.7 | |
| Version 9.2 | |
| Version 11.1.1.9.0 | |
| Version 11.1.1.9.0 | |
| From 8.6.0 to 8.6.3 | |
| Version 8.55 | |
| From 12.2.0 to 12.2.15 | |
| Version 10.4.6 | |
| From 12.2.0 to 12.2.15 | |
| From 16.2.0 to 16.2.11 | |
| From 17.7 to 17.12 | |
| From 2.3.0.1 to 2.3.0.3 | |
| Version 11.2.0.4 | |
| Version 14.0 | |
| Version 14.0 | |
| Version 15.0 | |
| Version 18.0 | |
| Version 14.0 | |
| Version 14.0 | |
| Version 11.1.1.9.0 | |
| Up to 19.8 | |
| Version 20.8 | |
| Version 2.3.0 | |
| Version 19.1 | |
| Version 8.5.1 | |
| Version 1.4.3 | |
| From 2.3.0.1 to 2.3.0.3 | |
| Version 12.2.1.3.0 | |
| Version 10.3.6.0.0 |
References (146)
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Mailing ListPatchThird Party Advisory
Source: cve@mitre.org
Mailing ListPatchThird Party Advisory
Source: cve@mitre.org
Mailing ListPatchThird Party Advisory
Source: cve@mitre.org
Broken LinkThird Party AdvisoryVDB Entry
Source: cve@mitre.org
Release NotesVendor Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Issue Tracking
Source: cve@mitre.org
Issue Tracking
Source: cve@mitre.org
Issue Tracking
Source: cve@mitre.org
Issue Tracking
Source: cve@mitre.org
Issue Tracking
Source: cve@mitre.org
Issue Tracking
Source: cve@mitre.org
Issue Tracking
Source: cve@mitre.org
Issue Tracking
Source: cve@mitre.org
Issue Tracking
Source: cve@mitre.org
Issue Tracking
Source: cve@mitre.org
Issue Tracking
Source: cve@mitre.org
Issue Tracking
Source: cve@mitre.org
Issue Tracking
Source: cve@mitre.org
Issue Tracking
Source: cve@mitre.org
Issue Tracking
Source: cve@mitre.org
Issue Tracking
Source: cve@mitre.org
Issue Tracking
Source: cve@mitre.org
Issue Tracking
Source: cve@mitre.org
Issue Tracking
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Issue TrackingMailing ListThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.