{"id":"GHSA-wv67-q8rr-grjp","summary":"Duplicate Advisory: Prototype Pollution in jquery","details":"## Duplicate Advisory\nThis advisory is a duplicate of [GHSA-6c3j-c64m-qhgq](https://github.com/advisories/GHSA-6c3j-c64m-qhgq). This link is maintained to preserve external references.\n\n## Original Description\nVersions of `jquery`  prior to 3.4.0 are vulnerable to Prototype Pollution. The extend() method allows an attacker to modify the prototype for `Object` causing changes in properties that will exist on all objects.\n\n## Recommendation\nUpgrade to version 3.4.0 or later.","aliases":["CVE-2019-5428"],"modified":"2026-09-10T03:48:10.211504561Z","published":"2019-04-23T15:59:10Z","withdrawn":"2019-04-26T14:50:56Z","database_specific":{"cwe_ids":[],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2019-04-23T15:57:18Z","nvd_published_at":null},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-5428"},{"type":"WEB","url":"https://github.com/jquery/jquery/pull/4333"},{"type":"WEB","url":"https://hackerone.com/reports/454365"},{"type":"WEB","url":"https://blog.jquery.com/2019/04/10/jquery-3-4-0-released"},{"type":"WEB","url":"https://www.npmjs.com/advisories/796"}],"affected":[{"package":{"name":"jquery","ecosystem":"npm","purl":"pkg:npm/jquery"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.4.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/04/GHSA-wv67-q8rr-grjp/GHSA-wv67-q8rr-grjp.json"}},{"package":{"name":"jquery","ecosystem":"NuGet","purl":"pkg:nuget/jquery"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.4.0"}]}],"versions":["1.10.0","1.10.0.1","1.10.1","1.10.2","1.11.0","1.11.1","1.11.2","1.11.3","1.12.0","1.12.1","1.12.2","1.12.3","1.12.4","1.4.1","1.4.2","1.4.3","1.4.4","1.5.0","1.5.1","1.5.2","1.6.0","1.6.1","1.6.2","1.6.3","1.6.4","1.7.0","1.7.1","1.7.1.1","1.7.2","1.8.0","1.8.1","1.8.2","1.8.3","1.9.0","1.9.1","2.0.0","2.0.1","2.0.1.1","2.0.2","2.0.3","2.1.0","2.1.1","2.1.2","2.1.3","2.1.4","2.2.0","2.2.1","2.2.2","2.2.3","2.2.4","3.0.0","3.0.0.1","3.1.0","3.1.1","3.2.1","3.3.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/04/GHSA-wv67-q8rr-grjp/GHSA-wv67-q8rr-grjp.json"}},{"package":{"name":"org.webjars.npm:jquery","ecosystem":"Maven","purl":"pkg:maven/org.webjars.npm/jquery"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.4.0"}]}],"versions":["1.11.0","1.11.1","1.11.3","1.12.1","1.12.2","1.12.3","1.12.4","1.7.2","1.7.3","1.8.2","1.8.3","1.9.1","2.1.0","2.1.1","2.1.1-rc1","2.1.1-rc2","2.1.3","2.1.4","2.2.0","2.2.1","2.2.2","2.2.3","2.2.4","3.0.0","3.0.0-alpha1","3.0.0-beta1","3.0.0-rc1","3.1.0","3.1.1","3.2.0","3.2.1","3.3.0","3.3.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/04/GHSA-wv67-q8rr-grjp/GHSA-wv67-q8rr-grjp.json"}},{"package":{"name":"jquery-rails","ecosystem":"RubyGems","purl":"pkg:gem/jquery-rails"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.4.0"}]}],"versions":["0.1.1","0.1.2","0.1.3","0.2","0.2.1","0.2.2","0.2.3","0.2.4","0.2.5","0.2.6","0.2.7","1.0","1.0.1","1.0.10","1.0.11","1.0.12","1.0.13","1.0.14","1.0.15","1.0.16","1.0.17","1.0.18","1.0.19","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9","1.0.rc","2.0.1","2.0.2","2.0.3","2.1.0","2.1.1","2.1.2","2.1.3","2.1.4","2.2.0","2.2.1","2.2.2","2.3.0","3.0.0","3.0.1","3.0.2","3.0.3","3.0.4","3.1.0","3.1.1","3.1.2","3.1.3","3.1.4","3.1.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/04/GHSA-wv67-q8rr-grjp/GHSA-wv67-q8rr-grjp.json"}}],"schema_version":"1.9.0"}