090502105 - jQuery.extend.Object.Prototype.Pollution
Description
This indicates an attack attempt to exploit an Object.Prototype Pollution Vulnerability in jQuery.
The vulnerability is due to improper validation of using jQuery.extend to manipulate source objects with enumerable __proto__ property. A remote attacker could exploit this to execute arbitrary code by overwriting or extending the native Object.prototype via passing crafted Javascript to modules using a vulnerable jQuery version.
Affected Products
jQuery prior to 3.4.0
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://blog.jquery.com/2019/04/10/jquery-3-4-0-released/
Version Updates
| Date | Version | Status | Detail |
|---|---|---|---|
| 2024-04-30 | 0.00375 |
New
|