CVE-2019-11358

Related Vulnerabilities: CVE-2019-11358  

Impact: Moderate Public Date: 2019-03-27 CWE: CWE-400 Bugzilla: 1701972: CVE-2019-11358 js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.

The MITRE CVE dictionary describes this issue as:

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.

Find out more about CVE-2019-11358 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 5.6
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Vector Network
Attack Complexity High
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Low
Integrity Impact Low
Availability Impact Low

Affected Packages State

Platform Package State
Red Hat Virtualization 4 ovirt-js-dependencies Under investigation
Red Hat Software Collections for Red Hat Enterprise Linux rh-python36-python-coverage Under investigation
Red Hat Software Collections for Red Hat Enterprise Linux python27-python-werkzeug Under investigation
Red Hat Software Collections for Red Hat Enterprise Linux python27-python-coverage Under investigation
Red Hat Software Collections for Red Hat Enterprise Linux rh-ror50-rubygem-jquery-rails Under investigation
Red Hat Software Collections for Red Hat Enterprise Linux rh-ror42-rubygem-jquery-rails Under investigation
Red Hat Software Collections for Red Hat Enterprise Linux rh-python35-python-coverage Under investigation
Red Hat Satellite 6 tfm-rubygem-jquery-ui-rails Under investigation
Red Hat Satellite 5 jquery-ui Under investigation
Red Hat Satellite 5 patternfly1 Under investigation
Red Hat OpenStack Platform 9.0 python-XStatic-jquery-ui Under investigation
Red Hat OpenStack Platform 9.0 python-XStatic-jQuery Under investigation
Red Hat OpenStack Platform 8.0 (Liberty) python-XStatic-jQuery Under investigation
Red Hat OpenStack Platform 8.0 (Liberty) python-XStatic-jquery-ui Under investigation
Red Hat OpenStack Platform 14.0 (Rocky) python-XStatic-jQuery Under investigation
Red Hat OpenStack Platform 14.0 (Rocky) python-XStatic-jquery-ui Under investigation
Red Hat OpenStack Platform 13.0 (Queens) python-XStatic-jQuery Under investigation
Red Hat OpenStack Platform 13.0 (Queens) python-XStatic-jquery-ui Under investigation
Red Hat OpenStack Platform 10 python-XStatic-jquery-ui Under investigation
Red Hat OpenStack Platform 10 python-XStatic-jQuery Under investigation
Red Hat JBoss Fuse 7 jquery Under investigation
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 python-XStatic-jquery-ui Under investigation
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 python-XStatic-jQuery Under investigation
Red Hat Enterprise Linux 7 pcp Under investigation
Red Hat Enterprise Linux 7 python-coverage Under investigation
Red Hat Enterprise Linux 7 pcp-webapp-graphite Under investigation
Red Hat Enterprise Linux 7 pcp-webapp-blinkenlights Under investigation
Red Hat Enterprise Linux 7 pki-core Under investigation
Red Hat Enterprise Linux 7 pcp-webjs Under investigation
Red Hat Enterprise Linux 7 publican Under investigation
Red Hat Enterprise Linux 7 ipa Under investigation
Red Hat Enterprise Linux 7 ipsilon Under investigation
Red Hat Enterprise Linux 6 python-coverage Under investigation
Red Hat Enterprise Linux 6 pcp-webapp-graphite Under investigation
Red Hat Enterprise Linux 6 ipa Under investigation
Red Hat Enterprise Linux 6 python-weberror Under investigation
Red Hat Enterprise Linux 6 pcp Under investigation
Red Hat Enterprise Linux 6 pcp-webjs Under investigation

External References