peter bassill · operator
$ cve CVE-2019-11358 JSON

CVE-2019-11358 EXPLOIT

6.1
MEDIUM · CVSS 3.1 · EPSS 87.2% (pctl 100)

Patch early

A public exploit exists.

Description

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.

Scoring

CVSS6.1 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS87.22% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-1321
On CISA KEVno
Public exploityes
Published2019-04-20
Last modified2026-06-17

Affected (40)

VendorProduct
backdropcmsbackdrop
debiandebian linux
drupaldrupal
fedoraprojectfedora
jqueryjquery
netapponcommand system manager
netappsnapcenter
opensusebackports sle
opensuseleap
oracleagile product lifecycle management for process
oracleapplication express
oracleapplication service level management
oracleapplication testing suite
oraclebanking digital experience
oraclebanking enterprise collections
oraclebanking platform
oraclebi publisher
oraclebig data discovery
oraclebusiness process management suite
oraclecommunications analytics
oraclecommunications application session controller
oraclecommunications billing and revenue management
oraclecommunications diameter signaling router
oraclecommunications eagle application processor
oraclecommunications element manager
oraclecommunications interactive session recorder
oraclecommunications operations monitor
oraclecommunications services gatekeeper
oraclecommunications session report manager
oraclecommunications session route manager
oraclecommunications unified inventory management
oraclecommunications webrtc session controller
oraclediagnostic assistant
oracleenterprise manager ops center
oracleenterprise session border controller
oraclefinancial services analytical applications infrastructure
oraclefinancial services analytical applications reconciliation framework
oraclefinancial services asset liability management
redhatcloudforms
redhatvirtualization manager

Public exploits

SourceTitleDate
exploit-dbjQuery 3.3.1 - Prototype Pollution & XSS Exploit2025-04-08

References

→ the Explorer  ·  watch your stack  ·  NVD