{
    "id": "CVE-2019-11358",
    "published": "2019-04-20 00:29:00",
    "last_modified": "2026-06-17 02:12:46",
    "cvss_score": "6.1",
    "cvss_severity": "MEDIUM",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
    "cwe": "CWE-1321",
    "description": "jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.",
    "epss_score": "0.87218",
    "epss_percentile": "0.99747",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-09-26 18:24:10",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "backdropcms",
            "product": "backdrop"
        },
        {
            "vendor": "debian",
            "product": "debian_linux"
        },
        {
            "vendor": "drupal",
            "product": "drupal"
        },
        {
            "vendor": "fedoraproject",
            "product": "fedora"
        },
        {
            "vendor": "jquery",
            "product": "jquery"
        },
        {
            "vendor": "netapp",
            "product": "oncommand_system_manager"
        },
        {
            "vendor": "netapp",
            "product": "snapcenter"
        },
        {
            "vendor": "opensuse",
            "product": "backports_sle"
        },
        {
            "vendor": "opensuse",
            "product": "leap"
        },
        {
            "vendor": "oracle",
            "product": "agile_product_lifecycle_management_for_process"
        },
        {
            "vendor": "oracle",
            "product": "application_express"
        },
        {
            "vendor": "oracle",
            "product": "application_service_level_management"
        },
        {
            "vendor": "oracle",
            "product": "application_testing_suite"
        },
        {
            "vendor": "oracle",
            "product": "banking_digital_experience"
        },
        {
            "vendor": "oracle",
            "product": "banking_enterprise_collections"
        },
        {
            "vendor": "oracle",
            "product": "banking_platform"
        },
        {
            "vendor": "oracle",
            "product": "bi_publisher"
        },
        {
            "vendor": "oracle",
            "product": "big_data_discovery"
        },
        {
            "vendor": "oracle",
            "product": "business_process_management_suite"
        },
        {
            "vendor": "oracle",
            "product": "communications_analytics"
        },
        {
            "vendor": "oracle",
            "product": "communications_application_session_controller"
        },
        {
            "vendor": "oracle",
            "product": "communications_billing_and_revenue_management"
        },
        {
            "vendor": "oracle",
            "product": "communications_diameter_signaling_router"
        },
        {
            "vendor": "oracle",
            "product": "communications_eagle_application_processor"
        },
        {
            "vendor": "oracle",
            "product": "communications_element_manager"
        },
        {
            "vendor": "oracle",
            "product": "communications_interactive_session_recorder"
        },
        {
            "vendor": "oracle",
            "product": "communications_operations_monitor"
        },
        {
            "vendor": "oracle",
            "product": "communications_services_gatekeeper"
        },
        {
            "vendor": "oracle",
            "product": "communications_session_report_manager"
        },
        {
            "vendor": "oracle",
            "product": "communications_session_route_manager"
        },
        {
            "vendor": "oracle",
            "product": "communications_unified_inventory_management"
        },
        {
            "vendor": "oracle",
            "product": "communications_webrtc_session_controller"
        },
        {
            "vendor": "oracle",
            "product": "diagnostic_assistant"
        },
        {
            "vendor": "oracle",
            "product": "enterprise_manager_ops_center"
        },
        {
            "vendor": "oracle",
            "product": "enterprise_session_border_controller"
        },
        {
            "vendor": "oracle",
            "product": "financial_services_analytical_applications_infrastructure"
        },
        {
            "vendor": "oracle",
            "product": "financial_services_analytical_applications_reconciliation_framework"
        },
        {
            "vendor": "oracle",
            "product": "financial_services_asset_liability_management"
        },
        {
            "vendor": "redhat",
            "product": "cloudforms"
        },
        {
            "vendor": "redhat",
            "product": "virtualization_manager"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "52141",
            "title": "jQuery 3.3.1 - Prototype Pollution & XSS Exploit",
            "date": "2025-04-08",
            "url": "https://www.exploit-db.com/exploits/52141"
        }
    ],
    "refs_list": [
        "http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00006.html",
        "http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00025.html",
        "http://packetstormsecurity.com/files/152787/dotCMS-5.1.1-Vulnerable-Dependencies.html",
        "http://packetstormsecurity.com/files/153237/RetireJS-CORS-Issue-Script-Execution.html",
        "http://packetstormsecurity.com/files/156743/OctoberCMS-Insecure-Dependencies.html",
        "http://seclists.org/fulldisclosure/2019/May/10",
        "http://seclists.org/fulldisclosure/2019/May/11",
        "http://seclists.org/fulldisclosure/2019/May/13",
        "http://www.openwall.com/lists/oss-security/2019/06/03/2",
        "http://www.securityfocus.com/bid/108023",
        "https://access.redhat.com/errata/RHBA-2019:1570",
        "https://access.redhat.com/errata/RHSA-2019:1456",
        "https://access.redhat.com/errata/RHSA-2019:2587",
        "https://access.redhat.com/errata/RHSA-2019:3023",
        "https://access.redhat.com/errata/RHSA-2019:3024",
        "https://backdropcms.org/security/backdrop-sa-core-2019-009",
        "https://blog.jquery.com/2019/04/10/jquery-3-4-0-released/",
        "https://github.com/jquery/jquery/commit/753d591aea698e57d6db58c9f722cd0808619b1b",
        "https://github.com/jquery/jquery/pull/4333",
        "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601",
        "https://lists.apache.org/thread.html/08720ef215ee7ab3386c05a1a90a7d1c852bf0706f176a7816bf65fc%40%3Ccommits.airflow.apache.org%3E",
        "https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E",
        "https://lists.apache.org/thread.html/5928aa293e39d248266472210c50f176cac1535220f2486e6a7fa844%40%3Ccommits.airflow.apache.org%3E",
        "https://lists.apache.org/thread.html/6097cdbd6f0a337bedd9bb5cc441b2d525ff002a96531de367e4259f%40%3Ccommits.airflow.apache.org%3E",
        "https://lists.apache.org/thread.html/88fb0362fd40e5b605ea8149f63241537b8b6fb5bfa315391fc5cbb7%40%3Ccommits.airflow.apache.org%3E"
    ]
}