You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable proto property, it could extend the native Object.prototype.
mend-bolt-for-githubbot
changed the title
CVE-2019-11358 (Medium) detected in detain/osrs-toolkit-php-4.0.1, jquery-1.3.2.js
CVE-2019-11358 (Medium) detected in detain/osrs-toolkit-php-4.0.1
Aug 31, 2022
mend-bolt-for-githubbot
changed the title
CVE-2019-11358 (Medium) detected in detain/osrs-toolkit-php-4.0.1
CVE-2019-11358 (Medium) detected in detain/osrs-toolkit-php-4.0.1, jquery-1.3.2.js
Sep 29, 2022
mend-bolt-for-githubbot
changed the title
CVE-2019-11358 (Medium) detected in detain/osrs-toolkit-php-4.0.1, jquery-1.3.2.js
CVE-2019-11358 (Medium) detected in detain/osrs-toolkit-php-4.0.1
Mar 29, 2024
mend-bolt-for-githubbot
changed the title
CVE-2019-11358 (Medium) detected in detain/osrs-toolkit-php-4.0.1
CVE-2019-11358 (Medium) detected in jquery-1.3.2.js, detain/osrs-toolkit-php-4.0.1
Mar 29, 2024
mend-bolt-for-githubbot
changed the title
CVE-2019-11358 (Medium) detected in jquery-1.3.2.js, detain/osrs-toolkit-php-4.0.1
CVE-2019-11358 (Medium) detected in detain/osrs-toolkit-php-4.0.1
Apr 13, 2024
mend-bolt-for-githubbot
changed the title
CVE-2019-11358 (Medium) detected in detain/osrs-toolkit-php-4.0.1
CVE-2019-11358 (Medium) detected in jquery-1.3.2.js, detain/osrs-toolkit-php-4.0.1
Jun 12, 2024
CVE-2019-11358 - Medium Severity Vulnerability
Vulnerable Libraries - jquery-1.3.2.js, detain/osrs-toolkit-php-4.0.1
jquery-1.3.2.js
JavaScript library for DOM operations
Library home page: https://cdnjs.cloudflare.com/ajax/libs/jquery/1.3.2/jquery.js
Path to vulnerable library: /vendor/detain/osrs-toolkit-php/demo/js/jquery-1.3.2.js
Dependency Hierarchy:
detain/osrs-toolkit-php-4.0.1
OpenSRS PHP Toolkit
Library home page: https://api.github.com/repos/detain/osrs-toolkit-php/zipball/c70929f690ee2d28bc4eeb46188295acba000f1e
Dependency Hierarchy:
Found in HEAD commit: 7588ad476215cc299f4cd6fac5a9613b73ca80ad
Found in base branch: master
Vulnerability Details
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable proto property, it could extend the native Object.prototype.
Publish Date: 2019-04-19
URL: CVE-2019-11358
CVSS 3 Score Details (6.1)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11358
Release Date: 2019-04-20
Fix Resolution: jquery - 3.4.0
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: