CVE-2019-11358Medium· 6.1▾ Twilight⚠ Exploited in the wildPoC availableXSS in jQuery as used in Drupal, Backdrop CMS, and other products
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 33.6 · likelihood 17.4 · exploitation 18
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
87%
Exploit-DB · 6 GitHub repos (last check)
jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
jquery >= 1.1.4, < 3.4.0jquery-rails < 4.3.4jQuery >= 1.1.4, < 3.4.0django >= 2.0a1, < 2.1.9django >= 2.2a1, < 2.2.2org.webjars.npm:jquery >= 1.1.4, < 3.4.0maximebf/debugbar < 1.19.0Upgrade to a patched release:
jquery 3.4.0jquery-rails 4.3.4jQuery 3.4.0django 2.1.9django 2.2.2org.webjars.npm:jquery 3.4.0maximebf/debugbar 1.19.0