Package        : jquery
Version        : 1.7.2+dfsg-3.2+deb8u6
CVE ID         : CVE-2019-11358

jQuery mishandles jQuery.extend(true, {}, ...) because of Object.prototype
pollution.  If an unsanitized source object contained an enumerable __proto__
property, it could extend the native Object.prototype. For additional
information, please refer to the upstream advisory at
https://www.drupal.org/sa-core-2019-006 .

For Debian 8 "Jessie", this problem has been fixed in version
1.7.2+dfsg-3.2+deb8u6.

We recommend that you upgrade your jquery packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-1777-1: jquery security update

May 6, 2019
jQuery mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution

Summary

We recommend that you upgrade your jquery packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
Package : jquery
Version : 1.7.2+dfsg-3.2+deb8u6
CVE ID : CVE-2019-11358

Related News