First published: Mon Apr 06 2020(Updated: )
python-XStatic-jQuery is the jQuery javascript library packaged for Python's setuptools<br>Security Fix(es):<br><li> prototype pollution in object's prototype leading to denial of service or</li> remote code execution or property injection (CVE-2019-11358)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2020:1325 is classified as moderate.
RHSA-2020:1325 addresses a prototype pollution vulnerability leading to denial of service, remote code execution, or property injection as identified in CVE-2019-11358.
To fix RHSA-2020:1325, you need to update the python-XStatic-jQuery package to the patched version provided in the security advisory.
Prototype pollution in RHSA-2020:1325 refers to the manipulation of an object's prototype to inject properties, which can lead to security vulnerabilities.
RHSA-2020:1325 is applicable to users of the python-XStatic-jQuery library who are at risk of the identified vulnerabilities.