Skip to main content
MEDIUM

CVE-2019-11358

CVSS v3

6.1

MEDIUM

EPSS Score

0.8 %

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.

Technical details

Published
2019-04-20
Exploit-DB
EDB-52141

Frequently asked questions

What is CVE-2019-11358?

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.

Is CVE-2019-11358 actively exploited?

Active exploitation of CVE-2019-11358 has not been confirmed. The EPSS score is 0.8%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-11358?

CVE-2019-11358 has a CVSS v3 base score of 6.1 (MEDIUM severity).

Is CVE-2019-11358 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key