CVE-2019-11358
high-risk
Published 2019-04-20
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
Do I need to act?
~
1.9% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
!
1 public exploit available
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
6
CVSS 6.1/10
Medium
NETWORK
/ LOW complexity
Affected Products (20)
Backdrop
Virtualization Manager
Agile Product Lifecycle Management For Process
Agile Product Lifecycle Management For Process
Agile Product Lifecycle Management For Process
Agile Product Lifecycle Management For Process
Agile Product Lifecycle Management For Process
Affected Vendors
References (146)
Third Party Advisory
http://packetstormsecurity.com/files/152787/dotCMS-5.1.1-Vulnerable-Dependencies...
Third Party Advisory
http://packetstormsecurity.com/files/153237/RetireJS-CORS-Issue-Script-Execution...
Third Party Advisory
http://packetstormsecurity.com/files/156743/OctoberCMS-Insecure-Dependencies.htm...
Mailing List
http://seclists.org/fulldisclosure/2019/May/10
Mailing List
http://seclists.org/fulldisclosure/2019/May/11
Mailing List
http://seclists.org/fulldisclosure/2019/May/13
Broken Link
http://www.securityfocus.com/bid/108023
Third Party Advisory
https://access.redhat.com/errata/RHBA-2019:1570
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:1456
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:2587
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:3023
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:3024
Third Party Advisory
https://backdropcms.org/security/backdrop-sa-core-2019-009
Third Party Advisory
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601
and 126 more references
61
/ 100
high-risk
Severity
23/34 · High
Exploitability
5/34 · Minimal
Exposure
33/34 · Critical