Lucene search

K
HistoryMay 13, 2019 - 1:57 a.m.

jQuery 2.2.4 is vulnerable to prototype pollution

2019-05-1301:57:29
jira.atlassian.com
477

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.024

Percentile

90.2%

Bitbucket Server comes with jQuery version 2.2.4. This version of jQuery is vulnerable to a security bug (CVE-2019-11358, [https://nvd.nist.gov/vuln/detail/CVE-2019-11358]) which is only fixed in jQuery 3.4.0.

Affected configurations

Vulners
Node
atlassianbitbucket_data_centerRange5.16.4
OR
atlassianbitbucket_data_centerRange6.0.4
OR
atlassianbitbucket_data_centerRange6.1.3
OR
atlassianbitbucket_data_centerRange6.2.1
OR
atlassianbitbucket_data_centerRange<5.16.5
OR
atlassianbitbucket_data_centerRange<6.0.5
OR
atlassianbitbucket_data_centerRange<6.1.4
OR
atlassianbitbucket_data_centerRange<6.2.1
VendorProductVersionCPE
atlassianbitbucket_data_center*cpe:2.3:a:atlassian:bitbucket_data_center:*:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.024

Percentile

90.2%