PT-2019-1889 · Jquery+9 · Jquery+9

Published

2019-03-25

·

Updated

2026-03-10

·

CVE-2019-11358

CVSS v3.1

6.1

Medium

AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions jQuery versions 1.1.4 through 3.4.0
Description The issue is related to the jQuery.extend() function, which mishandles the proto property, allowing an attacker to exploit Object.prototype pollution. This could lead to a denial of service, execution of arbitrary JavaScript code, or privilege escalation, depending on the context in which the function is used. The vulnerability can be exploited by a remote attacker using a specially crafted JavaScript object.
Recommendations For jQuery versions 1.1.4 through 3.4.0, update to version 3.4.0 or later to resolve the issue. As a temporary workaround, consider disabling the jQuery.extend(true, {}, ...) function until a patch is available. Restrict access to the vulnerable Object.prototype to minimize the risk of exploitation. Avoid using the proto property in the affected API endpoints until the issue is resolved.

Exploit

Fix

XSS

Prototype Pollution

Weakness Enumeration

Related Identifiers

ALSA-2020:4670
ALSA-2025_16880
ALT-PU-2019-2016
ALT-PU-2019-2054
ALT-PU-2020-3078
ALT-PU-2020-3096
BDU:2019-01542
BDU:2019-04254
CESA-2020_3936
CESA-2020_4670
CESA-2020_4847
CESA-2021_4142
CVE-2019-11358
DLA-1777-1
DLA-1777-2
DLA-1797-1
DLA-2118-1
DLA-3551-1
DRUPAL-CORE-2019-006
DSA-4434-1
DSA-4460-1
GHSA-6C3J-C64M-QHGQ
GHSA-JRPW-8884-2747
MGASA-2019-0279
OPENSUSE-SU-2019:1839-1
OPENSUSE-SU-2019:1872-1
OPENSUSE-SU-2019_1839-1
OPENSUSE-SU-2024:0231-1
OPENSUSE-SU-2024:11205-1
OPENSUSE-SU-2024:11242-1
OPENSUSE-SU-2024:13887-1
OPENSUSE-SU-2024:14208-1
OPENSUSE-SU-2026:10005-1
RHSA-2019:2587
RHSA-2019:3023
RHSA-2019:3024
RHSA-2020:1325
RHSA-2020:3936
RHSA-2020:4670
RHSA-2020:4847
RHSA-2020:5581
RHSA-2020_3936
RHSA-2020_4670
RHSA-2020_4847
RHSA-2021:4142
RHSA-2021_4142
RHSA-2022:7343
RHSA-2022_7343
RHSA-2023:0552
RHSA-2023:0553
RHSA-2023:0554
RHSA-2023:1043
RHSA-2023:1044
RHSA-2023:1045
RLSA-2020:4670
RLSA-2020:4847
RLSA-2021:4142
SNYK-JS-JQUERY-174006
USN-7622-1

Affected Products

Alt Linux
Almalinux
Centos
Jira
Junos
Red Hat
Rocky Linux
Suse
Ubuntu
Jquery