VDB

DRUPAL-CORE-2019-006

DRUPAL-CORE-2019-006 PUBLISHED CVSS 9.300000190734863 CRITICAL

The jQuery project released version 3.4.0, and as part of that, disclosed a security vulnerability that affects all prior versions. As described in their [release notes](https://blog.jquery.com/2019/04/10/jquery-3-4-0-released/): > jQuery 3.4.0 includes a fix for some unintended behavior when using jQuery.extend(true, {}, ...). If an unsanitized source object contained an enumerable \_\_proto\_\_ property, it could extend the native Object.prototype. This fix is included in jQuery 3.4.0, but patch diffs exist to patch previous jQuery versions. It's possible that this vulnerability is exploitable with some Drupal modules. As a precaution, this Drupal security release backports the fix to jQuery.extend(), without making any other changes to the jQuery version that is included in Drupal core (3.2.1 for Drupal 8 and 1.4.4 for Drupal 7) or running on the site via some other module such as [jQuery Update](https://www.drupal.org/project/jquery_update). *2019-04-22, edited to add CVE.*

Risk Scores

CVSS v4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
drupalcore8.0.0, 8.6.0, 8.0.0

Timeline

  • Apr 17, 2019 CVE Published
  • Mar 13, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›