UBUNTU-CVE-2019-11358
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-11358
UBUNTU-CVE-2019-11358
Summary:
Details: jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
References: https://ubuntu.com/security/CVE-2019-11358, https://www.drupal.org/sa-core-2019-006, https://blog.jquery.com/2019/04/10/jquery-3-4-0-released/, https://github.com/DanielRuf/snyk-js-jquery-174006?files=1, https://snyk.io/vuln/SNYK-JS-JQUERY-174006, https://backdropcms.org/security/backdrop-sa-core-2019-009, https://github.com/jquery/jquery/pull/4333, https://www.cve.org/CVERecord?id=CVE-2019-11358, https://ubuntu.com/security/notices/USN-7622-1
Affected packages
Package
Name: drupal7
Purl: pkg:deb/ubuntu/drupal7?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
