CVE-2019-11358

6.1
MEDIUMCVSS v3.1 Base Score
86.82%
HIGH RiskEPSS (100th percentile)

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.

Published: 4/20/2019
Modified: 6/17/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

6.1MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CVSS v2 Score

4.3

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS Score (Exploitation Probability)

86.82%HIGH Exploitation Risk
100th percentile

This vulnerability has a 86.82% probability of being exploited in the next 30 days, ranking higher than 100% of all scored CVEs.

CWE Classification

Advertisement