CVE-2019-11358 EXPLOIT
6.1
MEDIUM · CVSS 3.1 · EPSS 87.2% (pctl 100)
Patch early
A public exploit exists.
Description
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
Scoring
| CVSS | 6.1 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
| EPSS | 87.22% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-1321 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-04-20 |
| Last modified | 2026-06-17 |
Affected (40)
| Vendor | Product |
|---|---|
| backdropcms | backdrop |
| debian | debian linux |
| drupal | drupal |
| fedoraproject | fedora |
| jquery | jquery |
| netapp | oncommand system manager |
| netapp | snapcenter |
| opensuse | backports sle |
| opensuse | leap |
| oracle | agile product lifecycle management for process |
| oracle | application express |
| oracle | application service level management |
| oracle | application testing suite |
| oracle | banking digital experience |
| oracle | banking enterprise collections |
| oracle | banking platform |
| oracle | bi publisher |
| oracle | big data discovery |
| oracle | business process management suite |
| oracle | communications analytics |
| oracle | communications application session controller |
| oracle | communications billing and revenue management |
| oracle | communications diameter signaling router |
| oracle | communications eagle application processor |
| oracle | communications element manager |
| oracle | communications interactive session recorder |
| oracle | communications operations monitor |
| oracle | communications services gatekeeper |
| oracle | communications session report manager |
| oracle | communications session route manager |
| oracle | communications unified inventory management |
| oracle | communications webrtc session controller |
| oracle | diagnostic assistant |
| oracle | enterprise manager ops center |
| oracle | enterprise session border controller |
| oracle | financial services analytical applications infrastructure |
| oracle | financial services analytical applications reconciliation framework |
| oracle | financial services asset liability management |
| redhat | cloudforms |
| redhat | virtualization manager |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | jQuery 3.3.1 - Prototype Pollution & XSS Exploit | 2025-04-08 |
References
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00025.html
- http://packetstormsecurity.com/files/152787/dotCMS-5.1.1-Vulnerable-Dependencies.html
- http://packetstormsecurity.com/files/153237/RetireJS-CORS-Issue-Script-Execution.html
- http://packetstormsecurity.com/files/156743/OctoberCMS-Insecure-Dependencies.html
- http://seclists.org/fulldisclosure/2019/May/10
- http://seclists.org/fulldisclosure/2019/May/11
- http://seclists.org/fulldisclosure/2019/May/13
- http://www.openwall.com/lists/oss-security/2019/06/03/2
- http://www.securityfocus.com/bid/108023
- https://access.redhat.com/errata/RHBA-2019:1570
- https://access.redhat.com/errata/RHSA-2019:1456
- https://access.redhat.com/errata/RHSA-2019:2587
- https://access.redhat.com/errata/RHSA-2019:3023
- https://access.redhat.com/errata/RHSA-2019:3024
- https://backdropcms.org/security/backdrop-sa-core-2019-009
- https://blog.jquery.com/2019/04/10/jquery-3-4-0-released/
- https://github.com/jquery/jquery/commit/753d591aea698e57d6db58c9f722cd0808619b1b
- https://github.com/jquery/jquery/pull/4333
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601
→ the Explorer · watch your stack · NVD