{"id":"GHSA-jrpw-8884-2747","aliases":[],"url":"https://o3.security/vulnerability/GHSA-jrpw-8884-2747","summary":"eZ Platform Bundled jQuery affected by CVE-2019-11358","details":"In eZ Platform 2.x, ezsystems/ezplatform-admin-ui-assets before v4.2.0 includes jQuery version 3.3.1. This version of jQuery is affected by the security vulnerability https://www.cvedetails.com/cve/CVE-2019-11358/\nThis is fixed in jQuery version 3.4. We recommend that you upgrade your ezsystems/ezplatform-admin-ui-assets to v4.2.0 using Composer. This release includes jQuery 3.4.1.\n\n","published":"2024-05-15T21:08:41Z","modified":"2024-11-29T05:28:43.216002Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"ezsystems/ezplatform-admin-ui-assets","fixedVersion":"4.2.0"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/ezsystems/ezplatform-admin-ui-assets/2019-07-04-1.yaml"},{"type":"PACKAGE","url":"https://github.com/ezsystems/ezplatform-admin-ui-assets"},{"type":"WEB","url":"https://share.ez.no/community-project/security-advisories/ezsa-2019-005-bundled-jquery-affected-by-cve-2019-11358"},{"type":"WEB","url":"https://web.archive.org/web/20210614184115/https://share.ez.no/community-project/security-advisories/ezsa-2019-005-bundled-jquery-affected-by-cve-2019-11358"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-29T05:28:43.216002Z"}}