---
title: "CVE-2019-11358"
canonical: "https://kb.cynergy.app/space/MD/899285411/CVE-2019-11358"
format: markdown
---
**Description:**

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable **proto** property, it could extend the native Object.prototype.

**Published On:**

2019-03-27

**Updated On:**

2022-04-06

**Trending:**

FALSE

**CWE:**

CWE-1321

**Mitigation:**

![image](media://51a9f5a8-7b31-4b8b-8262-56ecf1d78939)

Cynergy has an automated mitigation capability that requires integration with your WAF provider. 

Once integrated, you can request “Protect with WAF” 

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately </span>

**Remediation:**

Update based on the vendor recommendations:

|  |  |  |  |  |  |
| --- | --- | --- | --- | --- | --- |
| Patch Id | Vendor | Fix Title | Fix Description | Fix Published On | Fix URL |
| RHSA-2020:3936 | OpenSource | ipa-4.6.8-5.el7 | An update for ipa is now available for Red Hat Enterprise Linux 7.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2022-04-24 | [https://access.redhat.com/errata/RHSA-2020:3936](https://access.redhat.com/errata/RHSA-2020:3936) |
| RHSA-2020:4847 | apache | jss-4.7.3-1.module+el8.3.0+8058+d5cd4219 | An update for the pki-core:10.6 and pki-deps:10.6 modules is now available for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2022-04-24 | [https://access.redhat.com/errata/RHSA-2020:4847](https://access.redhat.com/errata/RHSA-2020:4847) |
| RHSA-2020:4670 | OpenSource | bind-dyndb-ldap-11.3-1.module+el8.3.0+6993+104f8db0 | An update for the idm:DL1 and idm:client modules is now available for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2022-04-24 | [https://access.redhat.com/errata/RHSA-2020:4670](https://access.redhat.com/errata/RHSA-2020:4670) |
| MGASA-2019-0279 | mageia | Updated mediawiki packages fix security vulnerabilities | Updated mediawiki packages fix security vulnerabilities:<br>Potential XSS in jQuery (CVE-2019-11358).<br>An account can be logged out without using a token (CSRF) (CVE-2019-12466).<br>A spammer can use Special:ChangeEmail to send out spam with no rate limiting  
or ability to block them (CVE-2019-12467).<br>Directly POSTing to Special:ChangeEmail would allow for bypassing  
reauthentication, allowing for potential account takeover (CVE-2019-12468).<br>Exposed suppressed username or log in Special:EditTags (CVE-2019-12469).<br>Exposed suppressed log in RevisionDelete page (CVE-2019-12470).<br>Loading user JavaScript from a non-existent account allows anyone to create  
the account, and XSS the users' loading that script (CVE-2019-12471).<br>It is possible to bypass the limits on IP range blocks (`$wgBlockCIDRLimit`)  
by using the API (CVE-2019-12472).<br>Passing invalid titles to the API could cause a DoS by querying the entire  
`watchlist` table (CVE-2019-12473).<br>Privileged API responses that include whether a recent change has been  
patrolled may be cached publicly (CVE-2019-12474).<br>The mediawiki package has been updated to version 1.27.6 (Mageia 6) and 1.31.2  
(Mageia 7), fixing these issues and other bugs.  See the release announcements  
for more details. | 2019-09-16 | [http://advisories.mageia.org/MGASA-2019-0279.html](http://advisories.mageia.org/MGASA-2019-0279.html) |
| openSUSE-SU-2019:1839-1 | suse | Security update for python-Django | This update for python-Django fixes the following issues:<br>Security issues fixed:<br>- CVE-2019-11358: Fixed prototype pollution.
- CVE-2019-12308: Fixed XSS in AdminURLFieldWidget (bsc#1136468)
- CVE-2019-12781: Fixed incorrect HTTP detection with reverse-proxy connecting via HTTPS (bsc#1139945).
- CVE-2019-14232: Fixed denial-of-service possibility in ``django.utils.text.Truncator`` (bsc#1142880).
- CVE-2019-14233: Fixed denial-of-service possibility in ``strip_tags()`` (bsc#1142882).
- CVE-2019-14234: Fixed SQL injection possibility in key and index lookups for ``JSONField``/``HStoreField`` (bsc#1142883).
- CVE-2019-14235: Fixed potential memory exhaustion in ``django.utils.encoding.uri_to_iri()`` (bsc#1142885).<br>Non-security issues fixed:<br>- Fixed a migration crash on PostgreSQL when adding a check constraint with a contains lookup on DateRangeField or DateTimeRangeField, if the right hand side of an expression is the same type. | 2019-08-09 | [http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00006.html](http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00006.html) |
| CPUJul2019 | oracle | Oracle Critical Patch Update Advisory - July 2019 - Oracle CVRF | This document contains descriptions of Oracle product security vulnerabilities which have had fixes released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including fix distribution information can be found at the Oracle sites referenced in this document. | 2019-07-27 | [http://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html](http://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html) |
| CPUOct2019 | oracle | Oracle Critical Patch Update Advisory - October 2019 - Oracle CVRF | This document contains descriptions of Oracle product security vulnerabilities which have had security patches released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including security patch distribution information can be found at the Oracle sites referenced in this document. | 2019-10-17 | [http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html](http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html) |
| RHBA-2019:1570 | redhat | Red Hat Bug Fix Advisory: ovirt-engine-api-explorer bug fix and enhancement update for RHV 4.3.4 | Updated ovirt-engine-api-explorer packages that fix several bugs and add various enhancements are now available. | 2019-08-19 | [https://access.redhat.com/errata/RHBA-2019:1570](https://access.redhat.com/errata/RHBA-2019:1570) |
| RHSA-2019:1456 | redhat | Red Hat Security Advisory: Red Hat Single Sign-On 7.3.2 security update | A security update is now available for Red Hat Single Sign-On 7.3 from the Customer Portal.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2019-06-12 | [https://access.redhat.com/errata/RHSA-2019:1456](https://access.redhat.com/errata/RHSA-2019:1456) |
| RHSA-2019:2587 | redhat | Red Hat Security Advisory: CloudForms 4.7.9 security, bug fix and enhancement update | An update is now available for CloudForms Management Engine 5.10.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-05-20 | [https://access.redhat.com/errata/RHSA-2019:2587](https://access.redhat.com/errata/RHSA-2019:2587) |
| RHSA-2019:3023 | redhat | Red Hat Security Advisory: ovirt-engine-ui-extensions security and bug fix update | An update for ovirt-engine-ui-extensions is now available for Red Hat Virtualization Engine 4.3.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2019-10-11 | [https://access.redhat.com/errata/RHSA-2019:3023](https://access.redhat.com/errata/RHSA-2019:3023) |
| RHSA-2019:3024 | redhat | Red Hat Security Advisory: ovirt-web-ui security and bug fix update | An update for ovirt-web-ui is now available for Red Hat Virtualization Engine 4.3.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2019-10-11 | [https://access.redhat.com/errata/RHSA-2019:3024](https://access.redhat.com/errata/RHSA-2019:3024) |
| RHSA-2020:1325 | redhat | Red Hat Security Advisory: python-XStatic-jQuery security update | An update for python-XStatic-jQuery is now available for Red Hat OpenStack  
Platform 15 (Stein).<br>Red Hat Product Security has rated this update as having a security impact  
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which  
gives a detailed severity rating, is available for each vulnerability from  
the CVE link(s) in the References section. | 2020-04-08 | [https://access.redhat.com/errata/RHSA-2020:1325](https://access.redhat.com/errata/RHSA-2020:1325) |
| RHSA-2020:2412 | redhat | Red Hat Security Advisory: OpenShift Container Platform 4.5 container image security update | An update is now available for Red Hat OpenShift Container Platform 4.5.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-07-14 | [https://access.redhat.com/errata/RHSA-2020:2412](https://access.redhat.com/errata/RHSA-2020:2412) |
| RHSA-2020:3936 | redhat | Red Hat Security Advisory: ipa security, bug fix, and enhancement update | An update for ipa is now available for Red Hat Enterprise Linux 7.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-10-13 | [https://access.redhat.com/errata/RHSA-2020:3936](https://access.redhat.com/errata/RHSA-2020:3936) |
| RHSA-2020:4298 | redhat | Red Hat Security Advisory: OpenShift Container Platform 4.6.1 image security update | An update is now available for Red Hat OpenShift Container Platform 4.6.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-10-29 | [https://access.redhat.com/errata/RHSA-2020:4298](https://access.redhat.com/errata/RHSA-2020:4298) |
| RHSA-2020:4670 | redhat | Red Hat Security Advisory: idm:DL1 and idm:client security, bug fix, and enhancement update | An update for the idm:DL1 and idm:client modules is now available for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-11-05 | [https://access.redhat.com/errata/RHSA-2020:4670](https://access.redhat.com/errata/RHSA-2020:4670) |
| RHSA-2020:4847 | redhat | Red Hat Security Advisory: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update | An update for the pki-core:10.6 and pki-deps:10.6 modules is now available for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-11-05 | [https://access.redhat.com/errata/RHSA-2020:4847](https://access.redhat.com/errata/RHSA-2020:4847) |
| RHSA-2020:5581 | redhat | Red Hat Security Advisory: python-XStatic-jQuery security update | An update for python-XStatic-jQuery is now available for Red Hat OpenStack  
Platform 13 (Queens).<br>Red Hat Product Security has rated this update as having a security impact  
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which  
gives a detailed severity rating, is available for each vulnerability from  
the CVE link(s) in the References section. | 2020-12-19 | [https://access.redhat.com/errata/RHSA-2020:5581](https://access.redhat.com/errata/RHSA-2020:5581) |
| FEDORA-2019-1a3edd7e8a | fedora | Fedora 28 Update: drupal8-8.6.15-1.fc28 | - [https://www.drupal.org/project/drupal/releases/8.6.15](https://www.drupal.org/project/drupal/releases/8.6.15)      *<br>[https://www.drupal.org/SA-CORE-2019-005](https://www.drupal.org/SA-CORE-2019-005)  (CVE-2019-10909 / CVE-2019-10910 /  
CVE-2019-10911)     * [https://www.drupal.org/SA-CORE-2019-006](https://www.drupal.org/SA-CORE-2019-006)  (CVE-2019-11358) *  
[https://www.drupal.org/project/drupal/releases/8.6.14](https://www.drupal.org/project/drupal/releases/8.6.14) | 2019-05-09 | [https://bodhi.fedoraproject.org/updates/FEDORA-2019-1a3edd7e8a](https://bodhi.fedoraproject.org/updates/FEDORA-2019-1a3edd7e8a) |
| FEDORA-2019-2a0ce0c58c | fedora | Fedora 30 Update: drupal7-7.66-1.fc30 | - [https://www.drupal.org/project/drupal/releases/7.66](https://www.drupal.org/project/drupal/releases/7.66)      *<br>[https://www.drupal.org/SA-CORE-2019-006](https://www.drupal.org/SA-CORE-2019-006) | 2019-05-09 | [https://bodhi.fedoraproject.org/updates/FEDORA-2019-2a0ce0c58c](https://bodhi.fedoraproject.org/updates/FEDORA-2019-2a0ce0c58c) |
| FEDORA-2019-7eaf0bbe7c | fedora | Fedora 29 Update: drupal8-8.6.15-1.fc29 | - [https://www.drupal.org/project/drupal/releases/8.6.15](https://www.drupal.org/project/drupal/releases/8.6.15)      *<br>[https://www.drupal.org/SA-CORE-2019-005](https://www.drupal.org/SA-CORE-2019-005)  (CVE-2019-10909 / CVE-2019-10910 /  
CVE-2019-10911)     * [https://www.drupal.org/SA-CORE-2019-006](https://www.drupal.org/SA-CORE-2019-006)  (CVE-2019-11358) *  
[https://www.drupal.org/project/drupal/releases/8.6.14](https://www.drupal.org/project/drupal/releases/8.6.14) | 2019-05-09 | [https://bodhi.fedoraproject.org/updates/FEDORA-2019-7eaf0bbe7c](https://bodhi.fedoraproject.org/updates/FEDORA-2019-7eaf0bbe7c) |
| FEDORA-2019-a06dffab1c | fedora | Fedora 29 Update: drupal7-7.66-1.fc29 | - [https://www.drupal.org/project/drupal/releases/7.66](https://www.drupal.org/project/drupal/releases/7.66)      *<br>[https://www.drupal.org/SA-CORE-2019-006](https://www.drupal.org/SA-CORE-2019-006) | 2019-05-09 | [https://bodhi.fedoraproject.org/updates/FEDORA-2019-a06dffab1c](https://bodhi.fedoraproject.org/updates/FEDORA-2019-a06dffab1c) |
| FEDORA-2019-eba8e44ee6 | fedora | Fedora 30 Update: drupal8-8.6.15-1.fc30 | - [https://www.drupal.org/project/drupal/releases/8.6.15](https://www.drupal.org/project/drupal/releases/8.6.15)      *<br>[https://www.drupal.org/SA-CORE-2019-005](https://www.drupal.org/SA-CORE-2019-005)  (CVE-2019-10909 / CVE-2019-10910 /  
CVE-2019-10911)     * [https://www.drupal.org/SA-CORE-2019-006](https://www.drupal.org/SA-CORE-2019-006)  (CVE-2019-11358) *  
[https://www.drupal.org/project/drupal/releases/8.6.14](https://www.drupal.org/project/drupal/releases/8.6.14) | 2019-05-09 | [https://bodhi.fedoraproject.org/updates/FEDORA-2019-eba8e44ee6](https://bodhi.fedoraproject.org/updates/FEDORA-2019-eba8e44ee6) |
| FEDORA-2019-f563e66380 | fedora | Fedora 28 Update: drupal7-7.66-1.fc28 | - [https://www.drupal.org/project/drupal/releases/7.66](https://www.drupal.org/project/drupal/releases/7.66)      *<br>[https://www.drupal.org/SA-CORE-2019-006](https://www.drupal.org/SA-CORE-2019-006) | 2019-05-09 | [https://bodhi.fedoraproject.org/updates/FEDORA-2019-f563e66380](https://bodhi.fedoraproject.org/updates/FEDORA-2019-f563e66380) |
| openSUSE-SU-2019:1839-1 | suse | Security update for python-Django | This update for python-Django fixes the following issues:<br>Security issues fixed:<br>- CVE-2019-11358: Fixed prototype pollution.
- CVE-2019-12308: Fixed XSS in AdminURLFieldWidget (bsc#1136468)
- CVE-2019-12781: Fixed incorrect HTTP detection with reverse-proxy connecting via HTTPS (bsc#1139945).
- CVE-2019-14232: Fixed denial-of-service possibility in ``django.utils.text.Truncator`` (bsc#1142880).
- CVE-2019-14233: Fixed denial-of-service possibility in ``strip_tags()`` (bsc#1142882).
- CVE-2019-14234: Fixed SQL injection possibility in key and index lookups for ``JSONField``/``HStoreField`` (bsc#1142883).
- CVE-2019-14235: Fixed potential memory exhaustion in ``django.utils.encoding.uri_to_iri()`` (bsc#1142885).<br>Non-security issues fixed:<br>- Fixed a migration crash on PostgreSQL when adding a check constraint with a contains lookup on DateRangeField or DateTimeRangeField, if the right hand side of an expression is the same type. | 2021-04-16 | [https://lists.opensuse.org/opensuse-security-announce/2019-08/msg00006.html](https://lists.opensuse.org/opensuse-security-announce/2019-08/msg00006.html) |
| openSUSE-SU-2019:1872-1 | suse | Security update for python-Django | This update for python-Django fixes the following issues:<br>Security issues fixed:<br>- CVE-2019-11358: Fixed prototype pollution.
- CVE-2019-12308: Fixed XSS in AdminURLFieldWidget (bsc#1136468)
- CVE-2019-12781: Fixed incorrect HTTP detection with reverse-proxy connecting via HTTPS (bsc#1139945).
- CVE-2019-14232: Fixed denial-of-service possibility in ``django.utils.text.Truncator`` (bsc#1142880).
- CVE-2019-14233: Fixed denial-of-service possibility in ``strip_tags()`` (bsc#1142882).
- CVE-2019-14234: Fixed SQL injection possibility in key and index lookups for ``JSONField``/``HStoreField`` (bsc#1142883).
- CVE-2019-14235: Fixed potential memory exhaustion in ``django.utils.encoding.uri_to_iri()`` (bsc#1142885).<br>Non-security issues fixed:<br>- Fixed a migration crash on PostgreSQL when adding a check constraint with a contains lookup on DateRangeField or DateTimeRangeField, if the right hand side of an expression is the same type.<br>This update was imported from the openSUSE:Leap:15.1:Update update project. | 2022-03-25 | [https://lists.opensuse.org/opensuse-security-announce/2019-08/msg00025.html](https://lists.opensuse.org/opensuse-security-announce/2019-08/msg00025.html) |
| DSA-4434 | debian | DSA-4434-1 drupal7 -- security update | A cross-site scripting vulnerability has been found in Drupal, a  
fully-featured content management framework. For additional information,  
please refer to the upstream advisory at  
[https://www.drupal.org/sa-core-2019-006](https://www.drupal.org/sa-core-2019-006)  .  
For the stable distribution (stretch), this problem has been fixed in  
version 7.52-2+deb9u8.  
We recommend that you upgrade your drupal7 packages.  
For the detailed security status of drupal7 please refer to its security  
tracker page at:  
[https://security-tracker.debian.org/tracker/drupal7](https://security-tracker.debian.org/tracker/drupal7) | 2019-04-22 | [https://www.debian.org/security/2019/dsa-4434](https://www.debian.org/security/2019/dsa-4434) |
| SA-CORE-2019-006 | drupal | Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2019-006 | The jQuery project released version 3.4.0, and as part of that, disclosed a security vulnerability that affects all prior versions. As described in their release notes:jQuery 3.4.0 includes a fix for some unintended behavior when using jQuery.extend(true, {}, ...). If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. This fix is included in jQuery 3.4.0, but patch diffs exist to patch previous jQuery [versions.It](http://versions.It)'s possible that this vulnerability is exploitable with some Drupal modules. As a precaution, this Drupal security release backports the fix to jQuery.extend(), without making any other changes to the jQuery version that is included in Drupal core (3.2.1 for Drupal 8 and 1.4.4 for Drupal 7) or running on the site via some other module such as jQuery Update.2019-04-22, edited to add CVE. | 2019-07-17 | [https://www.drupal.org/sa-core-2019-006](https://www.drupal.org/sa-core-2019-006) |
| CPUApr2020 | oracle | Oracle Critical Patch Update Advisory - April 2020 - Oracle CVRF | This document contains descriptions of Oracle product security vulnerabilities which have had security patches released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including security patch distribution information can be found at the Oracle sites referenced in this document. | 2020-05-06 | [https://www.oracle.com/security-alerts/cpuapr2020.html](https://www.oracle.com/security-alerts/cpuapr2020.html) |
| CPUApr2021 | oracle | Oracle Critical Patch Update Advisory - April 2021 - Oracle CVRF | This document contains descriptions of Oracle product security vulnerabilities which have had security patches released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including security patch distribution information can be found at the Oracle sites referenced in this document. | 2021-05-06 | [https://www.oracle.com/security-alerts/cpuapr2021.html](https://www.oracle.com/security-alerts/cpuapr2021.html) |
| CPUJan2020 | oracle | Oracle Critical Patch Update Advisory - January 2020 - Oracle CVRF | This document contains descriptions of Oracle product security vulnerabilities which have had security patches released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including security patch distribution information can be found at the Oracle sites referenced in this document. | 2020-02-06 | [https://www.oracle.com/security-alerts/cpujan2020.html](https://www.oracle.com/security-alerts/cpujan2020.html) |
| CPUJan2021 | oracle | Oracle Critical Patch Update Advisory - January 2021 - Oracle CVRF | This document contains descriptions of Oracle product security vulnerabilities which have had security patches released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including security patch distribution information can be found at the Oracle sites referenced in this document. | 2021-05-06 | [https://www.oracle.com/security-alerts/cpujan2021.html](https://www.oracle.com/security-alerts/cpujan2021.html) |
| CPUJul2020 | oracle | Oracle Critical Patch Update Advisory - July 2020 - Oracle CVRF | This document contains descriptions of Oracle product security vulnerabilities which have had security patches released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including security patch distribution information can be found at the Oracle sites referenced in this document. | 2020-09-06 | [https://www.oracle.com/security-alerts/cpujul2020.html](https://www.oracle.com/security-alerts/cpujul2020.html) |
| CPUJul2021 | oracle | Oracle Critical Patch Update Advisory - July 2021 - Oracle CVRF | This document contains descriptions of Oracle product security vulnerabilities which have had security patches released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including security patch distribution information can be found at the Oracle sites referenced in this document. | 2021-08-25 | [https://www.oracle.com/security-alerts/cpujul2021.html](https://www.oracle.com/security-alerts/cpujul2021.html) |
| CPUOct2020 | oracle | Oracle Critical Patch Update Advisory - October 2020 - Oracle CVRF | This document contains descriptions of Oracle product security vulnerabilities which have had security patches released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including security patch distribution information can be found at the Oracle sites referenced in this document. | 2020-11-06 | [https://www.oracle.com/security-alerts/cpuoct2020.html](https://www.oracle.com/security-alerts/cpuoct2020.html) |
| CPUOct2021 | oracle | Oracle Critical Patch Update Advisory - October 2021 - Oracle CVRF | This document contains descriptions of Oracle product security vulnerabilities which have had security patches released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including security patch distribution information can be found at the Oracle sites referenced in this document. | 2021-11-06 | [https://www.oracle.com/security-alerts/cpuoct2021.html](https://www.oracle.com/security-alerts/cpuoct2021.html) |