Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-11358

78
FAUCET Score

CVE-2019-11358 describes a prototype pollution vulnerability in jQuery versions prior to 3.4.0, impacting products like Drupal and Backdrop CMS. This flaw allows an attacker to modify the native Object.prototype if an unsanitized source object containing an enumerable __proto__ property is processed by jQuery.extend(true, {}, ...). Rated as Medium severity (CVSS 6.1), it requires user interaction (UI:R) and could lead to partial confidentiality and integrity impacts (C:L/I:L). While not in the KEV catalog, an ExploitDB entry (EDB-52141) exists, and there is some community discussion, though no active exploitation or widespread media coverage is noted.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.4.0CPE matchmatch criteria
cpe:2.3:a:jquery:jquery:*:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
>= 7.0, < 7.66CPE matchmatch criteria
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.1MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
87.22%
Probability of exploitation in next 30 days
EPSS Percentile
99.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-52141 · Apr 8, 2025
This CVE's current EPSS score of 0.8722 is in the 100th percentile among its peer group of 26,219 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (91)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: azl3 python-pygments 2.5.2-1 on Azure Linux 3.0Fixed in: 2.7.4-1
microsoftpatch availablevia msrc
Product: azl3 orangefs 2.9.7-7 on Azure Linux 3.0Fixed in: 2.9.7-7
microsoftpatch availablevia msrc
Product: azl3 m2crypto 0.38.0-4 on Azure Linux 3.0Fixed in: 0.38.0-4
microsoftpatch availablevia msrc
Product: azl3 python-pygments 2.7.4-1 on Azure Linux 3.0Fixed in: 2.7.4-1
microsoftpatch availablevia msrc
Product: 16992-17084Fixed in: 0.38.0-4
microsoftpatch availablevia msrc
Product: 16992-16817Fixed in: 0.38.0-4
microsoftpatch availablevia msrc
Product: 16993-17084Fixed in: 2.7.4-1
microsoftpatch availablevia msrc
Product: 19947-17084Fixed in: 2.7.4-1
microsoftpatch availablevia msrc
Product: 16993-16817Fixed in: 2.7.4-1
microsoftpatch availablevia msrc
Product: 16994-17084Fixed in: 2.9.7-7
microsoftpatch availablevia msrc
Product: 16994-16817Fixed in: 2.9.7-7
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 2.7.4-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 2.7.4-1
oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: pki-deps:10.6-8030020200527165326.30b713e6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: pcs-0:0.10.10-4.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: jquery
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8Fixed in: eap7-hal-console-0:3.3.16-1.Final_redhat_00001.1.el8eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9Fixed in: eap7-hal-console-0:3.3.16-1.Final_redhat_00001.1.el9eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7Fixed in: eap7-hal-console-0:3.3.16-1.Final_redhat_00001.1.el7eap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: atomic-enterprise-service-catalog-1:3.11.170-1.git.1.91db82e.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: atomic-openshift-0:3.11.170-1.git.0.00cac56.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: atomic-openshift-cluster-autoscaler-0:3.11.170-1.git.1.0a0df6a.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: atomic-openshift-descheduler-0:3.11.170-1.git.1.9ad83f2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: atomic-openshift-dockerregistry-0:3.11.170-1.git.1.55fab05.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: atomic-openshift-metrics-server-0:3.11.170-1.git.1.357f177.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: atomic-openshift-node-problem-detector-0:3.11.170-1.git.1.b1f90a6.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: atomic-openshift-service-idler-0:3.11.170-1.git.1.8328979.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: atomic-openshift-web-console-0:3.11.170-1.git.1.3d64e8b.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: cri-o-0:1.11.16-0.5.dev.rhaos3.11.git3f89eba.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: golang-github-openshift-oauth-proxy-0:3.11.170-1.git.1.b49be83.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: golang-github-prometheus-alertmanager-0:3.11.170-1.git.1.61d7960.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: golang-github-prometheus-node_exporter-0:3.11.170-1.git.1.51473b7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: golang-github-prometheus-prometheus-0:3.11.170-1.git.1.227bc98.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: jenkins-0:2.204.2.1580891656-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: jenkins-2-plugins-0:3.11.1579107288-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: openshift-ansible-0:3.11.170-2.git.5.8802564.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: openshift-enterprise-autoheal-0:3.11.170-1.git.1.dfe6c52.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: openshift-enterprise-cluster-capacity-0:3.11.170-1.git.1.661684b.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: openshift-kuryr-0:3.11.170-1.git.1.7265da1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.5Fixed in: openshift4/ose-console:v4.5.0-202007012112.p0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 13.0 (Queens)Fixed in: python-XStatic-jQuery-0:2.2.4.1-3.el7ost
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUSFixed in: python-XStatic-jQuery-0:2.2.4.1-3.el7ost
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 15.0 (Stein)Fixed in: python-XStatic-jQuery-0:3.4.1.0-1.el8ost
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Single Sign-On 7Fixed in: keycloak-idp-jquery
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Single Sign-On 7.3.2 zip
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Single Sign-On 7.6 for RHEL 7Fixed in: rh-sso7-keycloak-0:18.0.6-1.redhat_00001.1.el7sso
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Single Sign-On 7.6 for RHEL 8Fixed in: rh-sso7-keycloak-0:18.0.6-1.redhat_00001.1.el8sso
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Single Sign-On 7.6 for RHEL 9Fixed in: rh-sso7-keycloak-0:18.0.6-1.redhat_00001.1.el9sso
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization Engine 4.3Fixed in: ovirt-engine-api-explorer-0:0.0.5-1.el7ev
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization Engine 4.3Fixed in: ovirt-engine-ui-extensions-0:1.0.10-1.el7ev
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization Engine 4.3Fixed in: ovirt-web-ui-0:1.6.0-1.el7ev
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rh-sso-7/sso76-openshift-rhel8:7.6-20
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.6Fixed in: openshift4/ose-prometheus:v4.6.0-202009290409.p0
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.10Fixed in: ansible-tower-0:3.5.2-1.el7at
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.10Fixed in: cfme-0:5.10.9.1-1.el7cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.10Fixed in: cfme-amazon-smartstate-0:5.10.9.1-1.el7cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.10Fixed in: cfme-appliance-0:5.10.9.1-1.el7cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.10Fixed in: cfme-gemset-0:5.10.9.1-1.el7cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.10Fixed in: ovirt-ansible-hosted-engine-setup-0:1.0.23-1.el7ev
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.10Fixed in: ovirt-ansible-roles-0:1.1.7-1.el7ev
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.10Fixed in: ovirt-ansible-vm-infra-0:1.1.19-1.el7ev
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.10Fixed in: v2v-conversion-host-0:1.14.2-1.el7ev
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: ipa-0:4.6.8-5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: pcs-0:0.9.169-3.el7_9.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: idm:client-8030020200923172426.05ac3f11
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: idm:DL1-8030020200923172343.9c827e52
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: pki-core:10.6-8030020200911215836.5ff1562f
View patch
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-grafana
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: ipa
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: pcp
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: python-coverage
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: python-weberror
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: ipsilon
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: pcp
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: pki-core
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: publican
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: python-coverage
redhatend of lifevia redhat_api
Product: Red Hat Fuse 7Fixed in: jquery
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: openshift3/grafana
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 10 (Newton)Fixed in: python-XStatic-jQuery
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 10 (Newton)Fixed in: python-XStatic-jquery-ui
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 9 (Mitaka)Fixed in: python-XStatic-jQuery
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 9 (Mitaka)Fixed in: python-XStatic-jquery-ui
redhatend of lifevia redhat_api
Product: Red Hat Software CollectionsFixed in: python27-python-coverage
redhatend of lifevia redhat_api
Product: Red Hat Software CollectionsFixed in: python27-python-werkzeug
redhatend of lifevia redhat_api
Product: Red Hat Software CollectionsFixed in: rh-python35-python-coverage
redhatend of lifevia redhat_api
Product: Red Hat Software CollectionsFixed in: rh-python36-python-coverage
redhatend of lifevia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: jquery
redhatend of lifevia redhat_api
Product: Red Hat Software CollectionsFixed in: rh-ror50-rubygem-jquery-rails

Vendor Advisories (4)

microsoft2024-Sep/CVE-2019-11358

CVE-2019-11358

Sep 10, 2024
rubygemsGHSA-6c3j-c64m-qhgqmedium

XSS in jQuery as used in Drupal, Backdrop CMS, and other products

Apr 26, 2019
microsoft2019-Apr/CVE-2019-11358Moderate

jQuery before 3.4.0 as used in Drupal Backdrop CMS and other products mishandles jQuery.extend(true {} ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property it could extend the native Object.prototype.

Apr 9, 2019
redhatCVE-2019-11358Moderate

jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection

Mar 27, 2019

References

lists.opensuse.org / opensuse-security-announce/2019-08/msg00006.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2019-08/msg00025.html
Mailing ListThird Party Advisory
packetstormsecurity.com / files/152787/dotCMS-5.1.1-Vulnerable-Dependencies.html
Third Party AdvisoryVDB Entry
packetstormsecurity.com / files/153237/RetireJS-CORS-Issue-Script-Execution.html
Third Party AdvisoryVDB Entry
packetstormsecurity.com / files/156743/OctoberCMS-Insecure-Dependencies.html
Third Party AdvisoryVDB Entry
access.redhat.com / errata/RHBA-2019:1570
Third Party Advisory
access.redhat.com / errata/RHSA-2019:1456
Third Party Advisory
access.redhat.com / errata/RHSA-2019:2587
Third Party Advisory
access.redhat.com / errata/RHSA-2019:3023
Third Party Advisory
access.redhat.com / errata/RHSA-2019:3024
Third Party Advisory
backdropcms.org / security/backdrop-sa-core-2019-009
Third Party Advisory
blog.jquery.com / 2019/04/10/jquery-3-4-0-released
Release NotesVendor Advisory
seclists.org / fulldisclosure/2019/May/10
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2019/May/11
Mailing ListPatchThird Party Advisory
seclists.org / fulldisclosure/2019/May/13
Mailing ListPatchThird Party Advisory
github.com / jquery/jquery/commit/753d591aea698e57d6db58c9f722cd0808619b1b
PatchThird Party Advisory
github.com / jquery/jquery/pull/4333
PatchThird Party Advisory
kb.pulsesecure.net / articles/Pulse_Security_Advisories/SA44601
Third Party Advisory
lists.apache.org / thread.html/08720ef215ee7ab3386c05a1a90a7d1c852bf0706f176a7816bf65fc%40%3Ccommits.airflow.apache.org%3E
Issue Tracking
lists.apache.org / thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
Issue Tracking
lists.apache.org / thread.html/5928aa293e39d248266472210c50f176cac1535220f2486e6a7fa844%40%3Ccommits.airflow.apache.org%3E
Issue Tracking
lists.apache.org / thread.html/6097cdbd6f0a337bedd9bb5cc441b2d525ff002a96531de367e4259f%40%3Ccommits.airflow.apache.org%3E
Issue Tracking
lists.apache.org / thread.html/88fb0362fd40e5b605ea8149f63241537b8b6fb5bfa315391fc5cbb7%40%3Ccommits.airflow.apache.org%3E
Issue Tracking
lists.apache.org / thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
Issue Tracking
lists.apache.org / thread.html/b736d0784cf02f5a30fbb4c5902762a15ad6d47e17e2c5a17b7d6205%40%3Ccommits.airflow.apache.org%3E
Issue Tracking
lists.apache.org / thread.html/ba79cf1658741e9f146e4c59b50aee56656ea95d841d358d006c18b6%40%3Ccommits.roller.apache.org%3E
Issue Tracking
lists.apache.org / thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E
Issue Tracking
lists.apache.org / thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E
Issue Tracking
lists.apache.org / thread.html/r2041a75d3fc09dec55adfd95d598b38d22715303f65c997c054844c9%40%3Cissues.flink.apache.org%3E
Issue Tracking
lists.apache.org / thread.html/r2baacab6e0acb5a2092eb46ae04fd6c3e8277b4fd79b1ffb7f3254fa%40%3Cissues.flink.apache.org%3E
Issue Tracking
lists.apache.org / thread.html/r38f0d1aa3c923c22977fe7376508f030f22e22c1379fbb155bf29766%40%3Cdev.syncope.apache.org%3E
Issue Tracking
lists.apache.org / thread.html/r41b5bfe009c845f67d4f68948cc9419ac2d62e287804aafd72892b08%40%3Cissues.flink.apache.org%3E
Issue Tracking
lists.apache.org / thread.html/r7aac081cbddb6baa24b75e74abf0929bf309b176755a53e3ed810355%40%3Cdev.flink.apache.org%3E
Issue Tracking
lists.apache.org / thread.html/r7d64895cc4dff84d0becfc572b20c0e4bf9bfa7b10c6f5f73e783734%40%3Cdev.storm.apache.org%3E
Issue Tracking
lists.apache.org / thread.html/r7e8ebccb7c022e41295f6fdb7b971209b83702339f872ddd8cf8bf73%40%3Cissues.flink.apache.org%3E
Issue Tracking
lists.apache.org / thread.html/rac25da84ecdcd36f6de5ad0d255f4e967209bbbebddb285e231da37d%40%3Cissues.flink.apache.org%3E
Issue Tracking
lists.apache.org / thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E
Issue Tracking
lists.debian.org / debian-lts-announce/2019/05/msg00006.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2019/05/msg00029.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2020/02/msg00024.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2023/08/msg00040.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/4UOAZIFCSZ3ENEFOR5IXX6NFAD3HV7FA
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/5IABSKTYZ5JUGL735UKGXL5YPRYOPUYI
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/KYH3OAGR2RTCHRA5NOKX2TES7SNQMWGO
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/QV3PKZC3PQCO3273HAT76PAQZFBEO4KP
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/RLXRX23725JL366CNZGJZ7AQQB7LHQ6F
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/WZW27UCJ5CYFL4KFFFMYMIBNMIU2ALG5
Mailing ListThird Party Advisory
seclists.org / bugtraq/2019/Apr/32
Mailing ListThird Party Advisory
seclists.org / bugtraq/2019/Jun/12
Issue TrackingMailing ListThird Party Advisory
seclists.org / bugtraq/2019/May/18
Mailing ListPatchThird Party Advisory
security.netapp.com / advisory/ntap-20190919-0001
Third Party Advisory
snyk.io / vuln/SNYK-JS-JQUERY-174006
ExploitThird Party Advisory
supportportal.juniper.net / s/article/2021-07-Security-Bulletin-Junos-OS-Multiple-J-Web-vulnerabilities-resolved-in-Junos-OS-21-2R1
Third Party Advisory
debian.org / security/2019/dsa-4434
Third Party Advisory
debian.org / security/2019/dsa-4460
Third Party Advisory
drupal.org / sa-core-2019-006
PatchThird Party Advisory
oracle.com / security-alerts/cpuapr2020.html
PatchThird Party Advisory
oracle.com / security-alerts/cpuApr2021.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujan2020.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujan2021.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujan2022.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujul2020.html
PatchThird Party Advisory
oracle.com / /security-alerts/cpujul2021.html
PatchThird Party Advisory
oracle.com / security-alerts/cpuoct2020.html
PatchThird Party Advisory
oracle.com / security-alerts/cpuoct2021.html
PatchThird Party Advisory
oracle.com / technetwork/security-advisory/cpujul2019-5072835.html
PatchThird Party Advisory
oracle.com / technetwork/security-advisory/cpuoct2019-5072832.html
PatchThird Party Advisory
privacy-wise.com / mitigating-cve-2019-11358-in-old-versions-of-jquery
PatchThird Party Advisory
synology.com / security/advisory/Synology_SA_19_19
Third Party Advisory
tenable.com / security/tns-2019-08
Third Party Advisory
tenable.com / security/tns-2020-02
Third Party Advisory
openwall.com / lists/oss-security/2019/06/03/2
Mailing ListPatchThird Party Advisory
securityfocus.com / bid/108023
Broken LinkThird Party AdvisoryVDB Entry