GHSA-wv67-q8rr-grjp

Suggest an improvement
Source
https://github.com/advisories/GHSA-wv67-q8rr-grjp
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/04/GHSA-wv67-q8rr-grjp/GHSA-wv67-q8rr-grjp.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-wv67-q8rr-grjp
Aliases
  • CVE-2019-5428
Withdrawn
2019-04-26T14:50:56Z
Published
2019-04-23T15:59:10Z
Modified
2026-09-10T03:48:10Z
Summary
Duplicate Advisory: Prototype Pollution in jquery
Details

Duplicate Advisory

This advisory is a duplicate of GHSA-6c3j-c64m-qhgq. This link is maintained to preserve external references.

Original Description

Versions of jquery prior to 3.4.0 are vulnerable to Prototype Pollution. The extend() method allows an attacker to modify the prototype for Object causing changes in properties that will exist on all objects.

Recommendation

Upgrade to version 3.4.0 or later.

Database specific
{
    "cwe_ids": [],
    "github_reviewed": true,
    "github_reviewed_at": "2019-04-23T15:57:18Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
}
References

Affected packages

npm / jquery

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.4.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/04/GHSA-wv67-q8rr-grjp/GHSA-wv67-q8rr-grjp.json"

NuGet / jquery

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.4.0

Affected versions

1.*
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.1.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.10.0
1.10.0.1
1.10.1
1.10.2
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
2.*
2.0.0
2.0.1
2.0.1.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.*
3.0.0
3.0.0.1
3.1.0
3.1.1
3.2.1
3.3.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/04/GHSA-wv67-q8rr-grjp/GHSA-wv67-q8rr-grjp.json"

Maven / org.webjars.npm:jquery

Package

Name
org.webjars.npm:jquery
View open source insights on deps.dev
Purl
pkg:maven/org.webjars.npm/jquery

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.4.0

Affected versions

1.*
1.7.2
1.7.3
1.8.2
1.8.3
1.9.1
1.11.0
1.11.1
1.11.3
1.12.1
1.12.2
1.12.3
1.12.4
2.*
2.1.0
2.1.1-rc1
2.1.1-rc2
2.1.1
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
3.*
3.0.0-alpha1
3.0.0-beta1
3.0.0-rc1
3.0.0
3.1.0
3.1.1
3.2.0
3.2.1
3.3.0
3.3.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/04/GHSA-wv67-q8rr-grjp/GHSA-wv67-q8rr-grjp.json"

RubyGems / jquery-rails

Package

Name
jquery-rails
Purl
pkg:gem/jquery-rails

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.4.0

Affected versions

0.*
0.1.1
0.1.2
0.1.3
0.2
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
1.*
1.0.rc
1.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
2.*
2.0.1
2.0.2
2.0.3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.2.0
2.2.1
2.2.2
2.3.0
3.*
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/04/GHSA-wv67-q8rr-grjp/GHSA-wv67-q8rr-grjp.json"