Description
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
Remediation
References
Related Vulnerabilities
MySQL CVE-2017-3639 Vulnerability (CVE-2017-3639)
Oracle JRE CVE-2013-2459 Vulnerability (CVE-2013-2459)
WordPress Plugin RestroPress-Online Food Ordering System Security Bypass (2.8.3)
Drupal Core 4.6.x Cross-Site Scripting (4.6.0 - 4.6.5)
osTicket Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2019-14749)