6.1

CVE-2019-11358

Exploit
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Jquery ≫ Jquery Version < 3.4.0
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Drupal ≫ Drupal Version >= 7.0 < 7.66
Drupal ≫ Drupal Version >= 8.5.0 < 8.5.15
Drupal ≫ Drupal Version >= 8.6.0 < 8.6.15
Backdropcms ≫ Backdrop Version >= 1.11.0 < 1.11.9
Backdropcms ≫ Backdrop Version >= 1.12.0 < 1.12.6
Fedoraproject ≫ Fedora Version 28
Fedoraproject ≫ Fedora Version 29
Fedoraproject ≫ Fedora Version 30
Opensuse ≫ Backports Sle Version 15.0 Update sp1
Opensuse ≫ Leap Version 15.1
Netapp ≫ Oncommand System Manager Version >= 3.0 <= 3.1.3
Netapp ≫ Snapcenter Version -
Redhat ≫ Cloudforms Version 4.7
Redhat ≫ Virtualization Manager Version 4.3
Oracle ≫ Application Express Version < 19.1
Oracle ≫ Application Testing Suite Version 12.5.0.3
Oracle ≫ Application Testing Suite Version 13.1.0.1
Oracle ≫ Application Testing Suite Version 13.2.0.1
Oracle ≫ Application Testing Suite Version 13.3.0.1
Oracle ≫ Banking Enterprise Collections Version >= 2.7.0 <= 2.8.0
Oracle ≫ Banking Platform Version >= 2.4.0 <= 2.10.0
Oracle ≫ Bi Publisher Version 5.5.0.0.0
Oracle ≫ Bi Publisher Version 12.2.1.3.0
Oracle ≫ Bi Publisher Version 12.2.1.4.0
Oracle ≫ Big Data Discovery Version 1.6
Oracle ≫ Business Process Management Suite Version 12.2.1.3.0
Oracle ≫ Business Process Management Suite Version 12.2.1.4.0
Oracle ≫ Communications Analytics Version 12.1.1
Oracle ≫ Communications Eagle Application Processor Version >= 16.1.0 <= 16.4.0
Oracle ≫ Communications Operations Monitor Version >= 4.1 <= 4.3
Oracle ≫ Diagnostic Assistant Version 2.12.36
Oracle ≫ Enterprise Manager Ops Center Version 12.4.0.0
Oracle ≫ Financial Services Data Foundation Version >= 8.0.4 <= 8.0.8
Oracle ≫ Financial Services Data Integration Hub Version >= 8.0.5 <= 8.0.7
Oracle ≫ Financial Services Funds Transfer Pricing Version >= 8.0.4 <= 8.0.7
Oracle ≫ Fusion Middleware Mapviewer Version 12.2.1.3.0
Oracle ≫ Healthcare Foundation Version 7.1.1
Oracle ≫ Healthcare Foundation Version 7.2.0
Oracle ≫ Healthcare Foundation Version 7.2.2
Oracle ≫ Healthcare Foundation Version 7.3.0
Oracle ≫ Hospitality Guest Access Version 4.2.0
Oracle ≫ Hospitality Guest Access Version 4.2.1
Oracle ≫ Hospitality Simphony Version >= 19.1.0 <= 19.1.2
Oracle ≫ Hospitality Simphony Version 18.1
Oracle ≫ Hospitality Simphony Version 18.2
Oracle ≫ Identity Manager Version 12.2.1.3.0
Oracle ≫ Insurance Data Foundation Version >= 8.0.4 <= 8.0.7
Oracle ≫ Insurance Insbridge Rating And Underwriting Version >= 5.0.0.0 <= 5.6.0.0
Oracle ≫ Jdeveloper Version 11.1.1.9.0
Oracle ≫ Jdeveloper Version 12.2.1.3.0
Oracle ≫ Jdeveloper Version 12.2.1.4.0
Oracle ≫ Jdeveloper And Adf Version 11.1.1.9.0
Oracle ≫ Jdeveloper And Adf Version 12.1.3.0.0
Oracle ≫ Jdeveloper And Adf Version 12.2.1.3.0
Oracle ≫ Knowledge Version >= 8.6.0 <= 8.6.3
Oracle ≫ Policy Automation Version >= 12.2.0 <= 12.2.15
Oracle ≫ Policy Automation Version 10.4.7
Oracle ≫ Policy Automation Version 12.1.0
Oracle ≫ Policy Automation Version 12.1.1
Oracle ≫ Policy Automation For Mobile Devices Version >= 12.2.0 <= 12.2.15
Oracle ≫ Primavera Gateway Version >= 16.2.0 <= 16.2.11
Oracle ≫ Primavera Gateway Version >= 17.12.0 <= 17.12.7
Oracle ≫ Primavera Gateway Version >= 18.8.0 <= 18.8.9
Oracle ≫ Primavera Gateway Version >= 19.12.0 <= 19.12.4
Oracle ≫ Primavera Gateway Version 15.2.18
Oracle ≫ Primavera Unifier Version >= 17.7 <= 17.12
Oracle ≫ Primavera Unifier Version 16.1
Oracle ≫ Primavera Unifier Version 16.2
Oracle ≫ Primavera Unifier Version 18.8
Oracle ≫ Real-time Scheduler Version >= 2.3.0.1 <= 2.3.0.3
Oracle ≫ Rest Data Services Version 11.2.0.4 SwEdition -
Oracle ≫ Rest Data Services Version 12.1.0.2 SwEdition -
Oracle ≫ Rest Data Services Version 12.2.0.1 SwEdition -
Oracle ≫ Rest Data Services Version 18c SwEdition -
Oracle ≫ Rest Data Services Version 19c SwEdition -
Oracle ≫ Retail Back Office Version 14.0
Oracle ≫ Retail Back Office Version 14.1
Oracle ≫ Retail Central Office Version 14.0
Oracle ≫ Retail Central Office Version 14.1
Oracle ≫ Retail Customer Insights Version 15.0
Oracle ≫ Retail Customer Insights Version 16.0
Oracle ≫ Retail Point-of-service Version 14.0
Oracle ≫ Retail Point-of-service Version 14.1
Oracle ≫ Service Bus Version 11.1.1.9.0
Oracle ≫ Service Bus Version 12.1.3.0.0
Oracle ≫ Service Bus Version 12.2.1.3.0
Oracle ≫ Siebel Mobile Applications Version <= 19.8
Oracle ≫ Siebel Ui Framework Version 20.8
Oracle ≫ System Utilities Version 19.1
Oracle ≫ Tape Library Acsls Version 8.5
Oracle ≫ Tape Library Acsls Version 8.5.1
Oracle ≫ Transportation Management Version 1.4.3
Oracle ≫ Utilities Mobile Workforce Management Version >= 2.3.0.1 <= 2.3.0.3
Oracle ≫ Webcenter Sites Version 12.2.1.3.0
Oracle ≫ Weblogic Server Version 10.3.6.0.0
Oracle ≫ Weblogic Server Version 12.1.3.0.0
Oracle ≫ Weblogic Server Version 12.2.1.3.0
Oracle ≫ Weblogic Server Version 12.2.1.4.0
Oracle ≫ Weblogic Server Version 14.1.1.0.0
Joomla ≫ Joomla! Version >= 3.0.0 <= 3.9.4
Juniper ≫ Junos Version 21.2 Update -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 87.22% 0.997
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

http://packetstormsecurity.com/files/152787/dotCMS-5.1.1-Vulnerable-Dependencies.html
Third Party Advisory
VDB Entry
http://seclists.org/fulldisclosure/2019/May/10
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2019/May/11
Patch
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2019/May/13
Patch
Third Party Advisory
Mailing List
https://seclists.org/bugtraq/2019/May/18
Patch
Third Party Advisory
Mailing List
https://www.oracle.com/security-alerts/cpujan2020.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html
Patch
Third Party Advisory
https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
Issue Tracking
https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
Issue Tracking
https://www.oracle.com//security-alerts/cpujul2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html
Patch
Third Party Advisory
https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
Issue Tracking
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2020.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2020.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2020.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html
Patch
Third Party Advisory
https://www.tenable.com/security/tns-2019-08
Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
Patch
Third Party Advisory
https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E
Issue Tracking
https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E
Issue Tracking
https://lists.apache.org/thread.html/ba79cf1658741e9f146e4c59b50aee56656ea95d841d358d006c18b6%40%3Ccommits.roller.apache.org%3E
Issue Tracking
http://packetstormsecurity.com/files/153237/RetireJS-CORS-Issue-Script-Execution.html
Third Party Advisory
VDB Entry
http://packetstormsecurity.com/files/156743/OctoberCMS-Insecure-Dependencies.html
Third Party Advisory
VDB Entry
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:1456
Third Party Advisory
https://access.redhat.com/errata/RHBA-2019:1570
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:3023
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:3024
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00006.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00025.html
Third Party Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2019/06/03/2
Patch
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/108023
Third Party Advisory
Broken Link
VDB Entry
https://access.redhat.com/errata/RHSA-2019:2587
Third Party Advisory
https://backdropcms.org/security/backdrop-sa-core-2019-009
Third Party Advisory
https://blog.jquery.com/2019/04/10/jquery-3-4-0-released/
Vendor Advisory
Release Notes
https://github.com/jquery/jquery/commit/753d591aea698e57d6db58c9f722cd0808619b1b
Patch
Third Party Advisory
https://github.com/jquery/jquery/pull/4333
Patch
Third Party Advisory
https://lists.apache.org/thread.html/08720ef215ee7ab3386c05a1a90a7d1c852bf0706f176a7816bf65fc%40%3Ccommits.airflow.apache.org%3E
Issue Tracking
https://lists.apache.org/thread.html/5928aa293e39d248266472210c50f176cac1535220f2486e6a7fa844%40%3Ccommits.airflow.apache.org%3E
Issue Tracking
https://lists.apache.org/thread.html/6097cdbd6f0a337bedd9bb5cc441b2d525ff002a96531de367e4259f%40%3Ccommits.airflow.apache.org%3E
Issue Tracking
https://lists.apache.org/thread.html/88fb0362fd40e5b605ea8149f63241537b8b6fb5bfa315391fc5cbb7%40%3Ccommits.airflow.apache.org%3E
Issue Tracking
https://lists.apache.org/thread.html/b736d0784cf02f5a30fbb4c5902762a15ad6d47e17e2c5a17b7d6205%40%3Ccommits.airflow.apache.org%3E
Issue Tracking
https://lists.apache.org/thread.html/r2041a75d3fc09dec55adfd95d598b38d22715303f65c997c054844c9%40%3Cissues.flink.apache.org%3E
Issue Tracking
https://lists.apache.org/thread.html/r2baacab6e0acb5a2092eb46ae04fd6c3e8277b4fd79b1ffb7f3254fa%40%3Cissues.flink.apache.org%3E
Issue Tracking
https://lists.apache.org/thread.html/r38f0d1aa3c923c22977fe7376508f030f22e22c1379fbb155bf29766%40%3Cdev.syncope.apache.org%3E
Issue Tracking
https://lists.apache.org/thread.html/r41b5bfe009c845f67d4f68948cc9419ac2d62e287804aafd72892b08%40%3Cissues.flink.apache.org%3E
Issue Tracking
https://lists.apache.org/thread.html/r7aac081cbddb6baa24b75e74abf0929bf309b176755a53e3ed810355%40%3Cdev.flink.apache.org%3E
Issue Tracking
https://lists.apache.org/thread.html/r7d64895cc4dff84d0becfc572b20c0e4bf9bfa7b10c6f5f73e783734%40%3Cdev.storm.apache.org%3E
Issue Tracking
https://lists.apache.org/thread.html/r7e8ebccb7c022e41295f6fdb7b971209b83702339f872ddd8cf8bf73%40%3Cissues.flink.apache.org%3E
Issue Tracking
https://lists.apache.org/thread.html/rac25da84ecdcd36f6de5ad0d255f4e967209bbbebddb285e231da37d%40%3Cissues.flink.apache.org%3E
Issue Tracking
https://lists.debian.org/debian-lts-announce/2019/05/msg00006.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2019/05/msg00029.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2020/02/msg00024.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4UOAZIFCSZ3ENEFOR5IXX6NFAD3HV7FA/
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5IABSKTYZ5JUGL735UKGXL5YPRYOPUYI/
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KYH3OAGR2RTCHRA5NOKX2TES7SNQMWGO/
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QV3PKZC3PQCO3273HAT76PAQZFBEO4KP/
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RLXRX23725JL366CNZGJZ7AQQB7LHQ6F/
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WZW27UCJ5CYFL4KFFFMYMIBNMIU2ALG5/
Third Party Advisory
Mailing List
https://seclists.org/bugtraq/2019/Apr/32
Third Party Advisory
Mailing List
https://seclists.org/bugtraq/2019/Jun/12
Third Party Advisory
Mailing List
Issue Tracking
https://security.netapp.com/advisory/ntap-20190919-0001/
Third Party Advisory
https://snyk.io/vuln/SNYK-JS-JQUERY-174006
Third Party Advisory
Exploit
https://supportportal.juniper.net/s/article/2021-07-Security-Bulletin-Junos-OS-Multiple-J-Web-vulnerabilities-resolved-in-Junos-OS-21-2R1
Third Party Advisory
https://www.debian.org/security/2019/dsa-4434
Third Party Advisory
https://www.debian.org/security/2019/dsa-4460
Third Party Advisory
https://www.drupal.org/sa-core-2019-006
Patch
Third Party Advisory
https://www.privacy-wise.com/mitigating-cve-2019-11358-in-old-versions-of-jquery/
Patch
Third Party Advisory
https://www.synology.com/security/advisory/Synology_SA_19_19
Third Party Advisory
https://www.tenable.com/security/tns-2020-02
Third Party Advisory