CVE-2019-11358
20.04.2019, 00:29
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
Vendor | Product | Version |
---|---|---|
jquery | jquery | 𝑥 < 3.4.0 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
drupal | drupal | 7.0 ≤ 𝑥 < 7.66 |
drupal | drupal | 8.5.0 ≤ 𝑥 < 8.5.15 |
drupal | drupal | 8.6.0 ≤ 𝑥 < 8.6.15 |
backdropcms | backdrop | 1.11.0 ≤ 𝑥 < 1.11.9 |
backdropcms | backdrop | 1.12.0 ≤ 𝑥 < 1.12.6 |
opensuse | backports_sle | 15.0:sp1 |
opensuse | leap | 15.1 |
netapp | oncommand_system_manager | 3.0 ≤ 𝑥 ≤ 3.1.3 |
netapp | snapcenter | - |
redhat | cloudforms | 4.7 |
redhat | virtualization_manager | 4.3 |
oracle | agile_product_lifecycle_management_for_process | 6.1 |
oracle | agile_product_lifecycle_management_for_process | 6.2.0.0 |
oracle | agile_product_lifecycle_management_for_process | 6.2.1.0 |
oracle | agile_product_lifecycle_management_for_process | 6.2.2.0 |
oracle | agile_product_lifecycle_management_for_process | 6.2.3.0 |
oracle | application_express | 𝑥 < 19.1 |
oracle | application_service_level_management | 13.2.0.0 |
oracle | application_service_level_management | 13.3.0.0 |
oracle | application_testing_suite | 12.5.0.3 |
oracle | application_testing_suite | 13.1.0.1 |
oracle | application_testing_suite | 13.2 |
oracle | application_testing_suite | 13.2.0.1 |
oracle | application_testing_suite | 13.3 |
oracle | application_testing_suite | 13.3.0.1 |
oracle | banking_digital_experience | 18.1 |
oracle | banking_digital_experience | 18.2 |
oracle | banking_digital_experience | 18.3 |
oracle | banking_digital_experience | 19.1 |
oracle | banking_digital_experience | 19.2 |
oracle | banking_digital_experience | 20.1 |
oracle | banking_enterprise_collections | 2.7.0 ≤ 𝑥 ≤ 2.8.0 |
oracle | banking_platform | 2.4.0 ≤ 𝑥 ≤ 2.10.0 |
oracle | bi_publisher | 5.5.0.0.0 |
oracle | bi_publisher | 12.2.1.3.0 |
oracle | bi_publisher | 12.2.1.4.0 |
oracle | big_data_discovery | 1.6 |
oracle | business_process_management_suite | 12.2.1.3.0 |
oracle | business_process_management_suite | 12.2.1.4.0 |
oracle | communications_analytics | 12.1.1 |
oracle | communications_application_session_controller | 3.8m0:m0 |
oracle | communications_billing_and_revenue_management | 7.5 |
oracle | communications_billing_and_revenue_management | 7.5.0.23.0 |
oracle | communications_billing_and_revenue_management | 12.0 |
oracle | communications_billing_and_revenue_management | 12.0.0.3.0 |
oracle | communications_diameter_signaling_router | 8.0.0 |
oracle | communications_diameter_signaling_router | 8.1 |
oracle | communications_diameter_signaling_router | 8.2 |
oracle | communications_diameter_signaling_router | 8.2.1 |
oracle | communications_eagle_application_processor | 16.1.0 ≤ 𝑥 ≤ 16.4.0 |
oracle | communications_element_manager | 8.1.1 |
oracle | communications_element_manager | 8.2.0 |
oracle | communications_element_manager | 8.2.1 |
oracle | communications_interactive_session_recorder | 6.0 ≤ 𝑥 ≤ 6.4 |
oracle | communications_operations_monitor | 4.1 ≤ 𝑥 ≤ 4.3 |
oracle | communications_operations_monitor | 3.4 |
oracle | communications_operations_monitor | 4.0 |
oracle | communications_operations_monitor | 4.1.0 |
oracle | communications_services_gatekeeper | 7.0 |
oracle | communications_session_report_manager | 8.1.1 |
oracle | communications_session_report_manager | 8.2.0 |
oracle | communications_session_report_manager | 8.2.1 |
oracle | communications_session_route_manager | 8.1.1 |
oracle | communications_session_route_manager | 8.2.0 |
oracle | communications_session_route_manager | 8.2.1 |
oracle | communications_unified_inventory_management | 7.3 |
oracle | communications_unified_inventory_management | 7.4.0 |
oracle | communications_webrtc_session_controller | 7.2 |
oracle | diagnostic_assistant | 2.12.36 |
oracle | enterprise_manager_ops_center | 12.3.3 |
oracle | enterprise_manager_ops_center | 12.4.0 |
oracle | enterprise_manager_ops_center | 12.4.0.0 |
oracle | enterprise_session_border_controller | 8.4 |
oracle | financial_services_analytical_applications_infrastructure | 7.3.3 ≤ 𝑥 ≤ 7.3.5 |
oracle | financial_services_analytical_applications_infrastructure | 8.0.2 ≤ 𝑥 ≤ 8.1.0 |
oracle | financial_services_analytical_applications_reconciliation_framework | 8.0.4 ≤ 𝑥 ≤ 8.0.7 |
oracle | financial_services_analytical_applications_reconciliation_framework | 8.1.0 |
oracle | financial_services_asset_liability_management | 8.0.4 ≤ 𝑥 ≤ 8.0.7 |
oracle | financial_services_asset_liability_management | 8.1.0 |
oracle | financial_services_balance_sheet_planning | 8.0.8 |
oracle | financial_services_basel_regulatory_capital_basic | 8.0.4 ≤ 𝑥 ≤ 8.0.7 |
oracle | financial_services_basel_regulatory_capital_basic | 8.1.0 |
oracle | financial_services_basel_regulatory_capital_internal_ratings_based_approach | 8.0.4 ≤ 𝑥 ≤ 8.0.7 |
oracle | financial_services_basel_regulatory_capital_internal_ratings_based_approach | 8.1.0 |
oracle | financial_services_data_foundation | 8.0.4 ≤ 𝑥 ≤ 8.0.8 |
oracle | financial_services_data_governance_for_us_regulatory_reporting | 8.0.6 ≤ 𝑥 ≤ 8.0.9 |
oracle | financial_services_data_integration_hub | 8.0.5 ≤ 𝑥 ≤ 8.0.7 |
oracle | financial_services_data_integration_hub | 8.1.0 |
oracle | financial_services_enterprise_financial_performance_analytics | 8.0.6 |
oracle | financial_services_enterprise_financial_performance_analytics | 8.0.7 |
oracle | financial_services_funds_transfer_pricing | 8.0.4 ≤ 𝑥 ≤ 8.0.7 |
oracle | financial_services_funds_transfer_pricing | 8.1.0 |
oracle | financial_services_hedge_management_and_ifrs_valuations | 8.0.4 ≤ 𝑥 ≤ 8.0.7 |
oracle | financial_services_hedge_management_and_ifrs_valuations | 8.1.0 |
oracle | financial_services_institutional_performance_analytics | 8.0.4 ≤ 𝑥 ≤ 8.0.7 |
oracle | financial_services_institutional_performance_analytics | 8.1.0 |
oracle | financial_services_liquidity_risk_management | 8.0.0.1.0 |
oracle | financial_services_liquidity_risk_management | 8.0.2 |
oracle | financial_services_liquidity_risk_management | 8.0.4.0.0 |
oracle | financial_services_liquidity_risk_management | 8.0.5.0.0 |
oracle | financial_services_liquidity_risk_management | 8.0.6 |
oracle | financial_services_liquidity_risk_measurement_and_management | 8.0.7 |
oracle | financial_services_liquidity_risk_measurement_and_management | 8.0.8 |
oracle | financial_services_liquidity_risk_measurement_and_management | 8.1.0 |
oracle | financial_services_loan_loss_forecasting_and_provisioning | 8.0.2 ≤ 𝑥 ≤ 8.0.7 |
oracle | financial_services_loan_loss_forecasting_and_provisioning | 8.1.0 |
oracle | financial_services_market_risk_measurement_and_management | 8.0.5 |
oracle | financial_services_market_risk_measurement_and_management | 8.0.6 |
oracle | financial_services_market_risk_measurement_and_management | 8.0.8 |
oracle | financial_services_price_creation_and_discovery | 8.0.4 ≤ 𝑥 ≤ 8.0.7 |
oracle | financial_services_profitability_management | 8.0.4 ≤ 𝑥 ≤ 8.0.7 |
oracle | financial_services_profitability_management | 8.1.0 |
oracle | financial_services_regulatory_reporting_for_de_nederlandsche_bank | 8.0.4 |
oracle | financial_services_regulatory_reporting_for_european_banking_authority | 8.0.6 |
oracle | financial_services_regulatory_reporting_for_european_banking_authority | 8.0.7 |
oracle | financial_services_regulatory_reporting_for_us_federal_reserve | 8.0.4 ≤ 𝑥 ≤ 8.0.7 |
oracle | financial_services_retail_customer_analytics | 8.0.4 ≤ 𝑥 ≤ 8.0.6 |
oracle | financial_services_retail_performance_analytics | 8.0.6 |
oracle | financial_services_retail_performance_analytics | 8.0.7 |
oracle | financial_services_revenue_management_and_billing | 2.4.0.0 |
oracle | financial_services_revenue_management_and_billing | 2.4.0.1 |
oracle | fusion_middleware_mapviewer | 12.2.1.3.0 |
oracle | healthcare_foundation | 7.1.1 |
oracle | healthcare_foundation | 7.2.0 |
oracle | healthcare_foundation | 7.2.2 |
oracle | healthcare_foundation | 7.3.0 |
oracle | healthcare_translational_research | 3.1.0 |
oracle | healthcare_translational_research | 3.2.1 |
oracle | healthcare_translational_research | 3.3.1 |
oracle | healthcare_translational_research | 3.3.2 |
oracle | healthcare_translational_research | 3.4.0 |
oracle | hospitality_guest_access | 4.2.0 |
oracle | hospitality_guest_access | 4.2.1 |
oracle | hospitality_materials_control | 18.1 |
oracle | hospitality_simphony | 19.1.0 ≤ 𝑥 ≤ 19.1.2 |
oracle | hospitality_simphony | 18.1 |
oracle | hospitality_simphony | 18.2 |
oracle | identity_manager | 12.2.1.3.0 |
oracle | insurance_accounting_analyzer | 8.0.9 |
oracle | insurance_allocation_manager_for_enterprise_profitability | 8.0.8 |
oracle | insurance_allocation_manager_for_enterprise_profitability | 8.1.0 |
oracle | insurance_data_foundation | 8.0.4 ≤ 𝑥 ≤ 8.0.7 |
oracle | insurance_ifrs_17_analyzer | 8.0.6 |
oracle | insurance_ifrs_17_analyzer | 8.0.7 |
oracle | insurance_insbridge_rating_and_underwriting | 5.0.0.0 ≤ 𝑥 ≤ 5.6.0.0 |
oracle | insurance_insbridge_rating_and_underwriting | 5.6.1.0 |
oracle | insurance_performance_insight | 8.0.7 |
oracle | jd_edwards_enterpriseone_tools | 9.2 |
oracle | jdeveloper | 11.1.1.9.0 |
oracle | jdeveloper | 12.2.1.3.0 |
oracle | jdeveloper | 12.2.1.4.0 |
oracle | jdeveloper_and_adf | 11.1.1.9.0 |
oracle | jdeveloper_and_adf | 12.1.3.0.0 |
oracle | jdeveloper_and_adf | 12.2.1.3.0 |
oracle | knowledge | 8.6.0 ≤ 𝑥 ≤ 8.6.3 |
oracle | peoplesoft_enterprise_peopletools | 8.55 |
oracle | peoplesoft_enterprise_peopletools | 8.56 |
oracle | peoplesoft_enterprise_peopletools | 8.57 |
oracle | peoplesoft_enterprise_peopletools | 8.58 |
oracle | policy_automation | 12.2.0 ≤ 𝑥 ≤ 12.2.15 |
oracle | policy_automation | 10.4.7 |
oracle | policy_automation | 12.1.0 |
oracle | policy_automation | 12.1.1 |
oracle | policy_automation_connector_for_siebel | 10.4.6 |
oracle | policy_automation_for_mobile_devices | 12.2.0 ≤ 𝑥 ≤ 12.2.15 |
oracle | primavera_gateway | 16.2.0 ≤ 𝑥 ≤ 16.2.11 |
oracle | primavera_gateway | 17.12.0 ≤ 𝑥 ≤ 17.12.7 |
oracle | primavera_gateway | 18.8.0 ≤ 𝑥 ≤ 18.8.9 |
oracle | primavera_gateway | 19.12.0 ≤ 𝑥 ≤ 19.12.4 |
oracle | primavera_gateway | 15.2.18 |
oracle | primavera_unifier | 17.7 ≤ 𝑥 ≤ 17.12 |
oracle | primavera_unifier | 16.1 |
oracle | primavera_unifier | 16.2 |
oracle | primavera_unifier | 18.8 |
oracle | real-time_scheduler | 2.3.0.1 ≤ 𝑥 ≤ 2.3.0.3 |
oracle | rest_data_services | 11.2.0.4 |
oracle | rest_data_services | 12.1.0.2 |
oracle | rest_data_services | 12.2.0.1 |
oracle | retail_back_office | 14.0 |
oracle | retail_back_office | 14.1 |
oracle | retail_central_office | 14.0 |
oracle | retail_central_office | 14.1 |
oracle | retail_customer_insights | 15.0 |
oracle | retail_customer_insights | 16.0 |
oracle | retail_customer_management_and_segmentation_foundation | 18.0 |
oracle | retail_customer_management_and_segmentation_foundation | 19.0 |
oracle | retail_point-of-service | 14.0 |
oracle | retail_point-of-service | 14.1 |
oracle | retail_returns_management | 14.0 |
oracle | retail_returns_management | 14.1 |
oracle | service_bus | 11.1.1.9.0 |
oracle | service_bus | 12.1.3.0.0 |
oracle | service_bus | 12.2.1.3.0 |
oracle | siebel_mobile_applications | 𝑥 ≤ 19.8 |
oracle | siebel_ui_framework | 20.8 |
oracle | storagetek_tape_analytics_sw_tool | 2.3.0 |
oracle | system_utilities | 19.1 |
oracle | tape_library_acsls | 8.5 |
oracle | tape_library_acsls | 8.5.1 |
oracle | transportation_management | 1.4.3 |
oracle | utilities_mobile_workforce_management | 2.3.0.1 ≤ 𝑥 ≤ 2.3.0.3 |
oracle | webcenter_sites | 12.2.1.3.0 |
oracle | weblogic_server | 10.3.6.0.0 |
oracle | weblogic_server | 12.1.3.0.0 |
oracle | weblogic_server | 12.2.1.3.0 |
oracle | weblogic_server | 12.2.1.4.0 |
oracle | weblogic_server | 14.1.1.0.0 |
joomla | joomla\! | 3.0.0 ≤ 𝑥 ≤ 3.9.4 |
juniper | junos | 21.2 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
mediawiki |
| ||||||||||||||
node-jquery |
| ||||||||||||||
otrs2 |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
drupal7 |
| ||||||||||||||||||||||||||||||
jquery |
| ||||||||||||||||||||||||||||||
mediawiki |
| ||||||||||||||||||||||||||||||
node-jquery |
| ||||||||||||||||||||||||||||||
otrs2 |
|
References