[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

[3.10] drupal7: Cross Site Scripting (CVE-2019-11358)

ID: oval:org.secpod.oval:def:1801478Date: (C)2019-06-27   (M)2024-04-17
Class: PATCHFamily: unix




jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend because of Object.prototype pollution. If an unsanitized source object contained an enumerable proto property, it could extend the native Object.prototype. Fixed In Version:¶ drupal 7.66

Platform:
Alpine Linux 3.10
Product:
drupal7
Reference:
10317
CVE-2019-11358
CVE    1
CVE-2019-11358
CPE    2
cpe:/a:drupal:drupal7
cpe:/o:alpinelinux:alpine_linux:3.10

© SecPod Technologies