GHSA-wv67-q8rr-grjp
Dashboard / Vulnerabilities / GHSA-wv67-q8rr-grjp
Summary: Duplicate Advisory: Prototype Pollution in jquery
Details: ## Duplicate Advisory This advisory is a duplicate of [GHSA-6c3j-c64m-qhgq](https://github.com/advisories/GHSA-6c3j-c64m-qhgq). This link is maintained to preserve external references. ## Original Description Versions of `jquery` prior to 3.4.0 are vulnerable to Prototype Pollution. The extend() method allows an attacker to modify the prototype for `Object` causing changes in properties that will exist on all objects. ## Recommendation Upgrade to version 3.4.0 or later.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-5428, https://github.com/jquery/jquery/pull/4333, https://hackerone.com/reports/454365, https://blog.jquery.com/2019/04/10/jquery-3-4-0-released, https://www.npmjs.com/advisories/796
Affected packages
Package
Name: jquery
Purl: pkg:npm/jquery
Affected ranges
Type: SEMVER
Events:
