Lucene search

K
typo3TYPO3 AssociationTYPO3-PSA-2019-004
HistoryMay 07, 2019 - 12:00 a.m.

Cross-Site Scripting in jQuery before 3.4.0

2019-05-0700:00:00
TYPO3 Association
typo3.org
79

0.035 Low

EPSS

Percentile

91.6%

jQuery before 3.4.0 mishandles jQuery.extend(true, {}, …) because of Object.prototype pollution. If an unsanitized source object contained an enumerable proto property, it could extend the native Object.prototype.

CPENameOperatorVersion
component: jqueryeq3.4.0