Vulnerabilities/

XSS in jQuery as used in Drupal, Backdrop CMS, and other products

Severity:
Medium

Description

jQuery from 1.1.4 until 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.

Recommendation

Update the jquery package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
jquery
Anything's wrong? Let us know Last updated on November 05, 2024

This issue is available in SmartScanner Professional

See Pricing