CVE-2019-11358

Aliases:GHSA-6c3j-c64m-qhgqDRUPAL-CORE-2019-006
Advisory lineage Upstream: 0 Downstream: 35
Modified
Published: 19 Apr 2019, 00:00
Last modified:15 Nov 2024, 15:11

Vulnerability Summary

Overall Risk (default)
medium
35/100
CVSS Score
6.1 MEDIUM
v3.1 (nvd)
EPSS Score
1.53% LOW
2% probability -0.94%
KEV
Not listed
Ransomware
No reports
Public exploits
2 found
Dark Web
Not detected

Timeline

19 Apr 2019, 00:00
Published
Vulnerability first disclosed
15 Nov 2024, 15:11
Last Modified
Vulnerability information updated

Description

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.

CVSS Metrics

  • v3.1MEDIUMScore: 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS Trends

Current EPSS score: 1.53% Percentile: 82%

Techniques & Countermeasures

  • CWE-1321Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

    The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Affected Systems

  • backdropcmsbackdrop

    ≥ 1.11.0, < 1.11.9 | ≥ 1.12.0, < 1.12.6

  • maximebfdebugbar

    < 1.19.0

  • debiandebian_linux

    8.0 | 9.0 | 10.0

  • drupaldrupal

    ≥ 7.0, < 7.66 | ≥ 8.5.0, < 8.5.15 | ≥ 8.6.0, < 8.6.15

  • fedoraprojectfedora

    28 | 29 | 30

  • RubyGemsjquery-rails

    < 4.3.4

  • UnknownJoomla!

    ≥ 3.0.0, ≤ 3.9.4

  • UnknownJQuery

    < 3.4.0

  • juniperjunos

    21.2

  • org.webjars.npmjquery

    ≥ 1.1.4, < 3.4.0

  • netapponcommand_system_manager

    ≥ 3.0, ≤ 3.1.3

  • netappsnapcenter

    na

  • Npmjquery

    ≥ 1.1.4, < 3.4.0

  • NuGetjquery

    ≥ 1.1.4, < 3.4.0

  • opensusebackports_sle

    15.0:sp1

  • opensuseleap

    15.1

  • oracleagile_product_lifecycle_management_for_process

    6.1 | 6.2.0.0 | 6.2.1.0 | 6.2.2.0 | 6.2.3.0

  • oracleapplication_express

    < 19.1

  • oracleapplication_service_level_management

    13.2.0.0 | 13.3.0.0

  • oracleapplication_testing_suite

    12.5.0.3 | 13.1.0.1 | 13.2 | 13.2.0.1 | 13.3 | 13.3.0.1

  • oraclebanking_digital_experience

    18.1 | 18.2 | 18.3 | 19.1 | 19.2 | 20.1

  • oraclebanking_enterprise_collections

    ≥ 2.7.0, ≤ 2.8.0

  • oraclebanking_platform

    ≥ 2.4.0, ≤ 2.10.0

  • oraclebi_publisher

    5.5.0.0.0 | 12.2.1.3.0 | 12.2.1.4.0

  • oraclebig_data_discovery

    1.6

  • oraclebusiness_process_management_suite

    12.2.1.3.0 | 12.2.1.4.0

  • oraclecommunications_analytics

    12.1.1

  • oraclecommunications_application_session_controller

    3.8m0

  • oraclecommunications_billing_and_revenue_management

    7.5 | 7.5.0.23.0 | 12.0 | 12.0.0.3.0

  • oraclecommunications_diameter_signaling_router

    8.0.0 | 8.1 | 8.2 | 8.2.1

  • oraclecommunications_eagle_application_processor

    ≥ 16.1.0, ≤ 16.4.0

  • oraclecommunications_element_manager

    8.1.1 | 8.2.0 | 8.2.1

  • oraclecommunications_interactive_session_recorder

    ≥ 6.0, ≤ 6.4

  • oraclecommunications_operations_monitor

    ≥ 4.1, ≤ 4.3 | 3.4 | 4.0 | 4.1.0

  • oraclecommunications_services_gatekeeper

    7.0

  • oraclecommunications_session_report_manager

    8.1.1 | 8.2.0 | 8.2.1

  • oraclecommunications_session_route_manager

    8.1.1 | 8.2.0 | 8.2.1

  • oraclecommunications_unified_inventory_management

    7.3 | 7.4.0

  • oraclecommunications_webrtc_session_controller

    7.2

  • oraclediagnostic_assistant

    2.12.36

  • oracleenterprise_manager_ops_center

    12.3.3 | 12.4.0 | 12.4.0.0

  • oracleenterprise_session_border_controller

    8.4

  • oraclefinancial_services_analytical_applications_infrastructure

    ≥ 7.3.3, ≤ 7.3.5 | ≥ 8.0.2, ≤ 8.1.0

  • oraclefinancial_services_analytical_applications_reconciliation_framework

    ≥ 8.0.4, ≤ 8.0.7 | 8.1.0

  • oraclefinancial_services_asset_liability_management

    ≥ 8.0.4, ≤ 8.0.7 | 8.1.0

  • oraclefinancial_services_balance_sheet_planning

    8.0.8

  • oraclefinancial_services_basel_regulatory_capital_basic

    ≥ 8.0.4, ≤ 8.0.7 | 8.1.0

  • oraclefinancial_services_basel_regulatory_capital_internal_ratings_based_approach

    ≥ 8.0.4, ≤ 8.0.7 | 8.1.0

  • oraclefinancial_services_data_foundation

    ≥ 8.0.4, ≤ 8.0.8

  • oraclefinancial_services_data_governance_for_us_regulatory_reporting

    ≥ 8.0.6, ≤ 8.0.9

Showing first 50 affected entries in server-rendered view.

References (119)