QID 980287
QID 980287: Nodejs (npm) Security Update for jquery (GHSA-6c3j-c64m-qhgq)
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-6c3j-c64m-qhgq for updates pertaining to this vulnerability.
Vendor References
- GHSA-6c3j-c64m-qhgq -
github.com/advisories/GHSA-6c3j-c64m-qhgq
CVEs related to QID 980287
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6c3j-c64m-qhgq | jquery |
|