jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
https://www.tenable.com/security/tns-2020-02
https://www.tenable.com/security/tns-2019-08
https://www.synology.com/security/advisory/Synology_SA_19_19
https://www.privacy-wise.com/mitigating-cve-2019-11358-in-old-versions-of-jquery/
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
https://www.oracle.com/security-alerts/cpuoct2021.html
https://www.oracle.com/security-alerts/cpuoct2020.html
https://www.oracle.com/security-alerts/cpujul2020.html
https://www.oracle.com/security-alerts/cpujan2022.html
https://www.oracle.com/security-alerts/cpujan2021.html
https://www.oracle.com/security-alerts/cpujan2020.html
https://www.oracle.com/security-alerts/cpuapr2020.html
https://www.oracle.com/security-alerts/cpuApr2021.html
https://www.oracle.com//security-alerts/cpujul2021.html
https://www.drupal.org/sa-core-2019-006
https://www.debian.org/security/2019/dsa-4460
https://www.debian.org/security/2019/dsa-4434
https://snyk.io/vuln/SNYK-JS-JQUERY-174006
https://security.netapp.com/advisory/ntap-20190919-0001/
https://seclists.org/bugtraq/2019/May/18
https://seclists.org/bugtraq/2019/Jun/12
https://seclists.org/bugtraq/2019/Apr/32
https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html
https://lists.debian.org/debian-lts-announce/2020/02/msg00024.html
https://lists.debian.org/debian-lts-announce/2019/05/msg00029.html
https://lists.debian.org/debian-lts-announce/2019/05/msg00006.html
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601
https://github.com/jquery/jquery/pull/4333
https://github.com/jquery/jquery/commit/753d591aea698e57d6db58c9f722cd0808619b1b
https://blog.jquery.com/2019/04/10/jquery-3-4-0-released/
https://backdropcms.org/security/backdrop-sa-core-2019-009
https://access.redhat.com/errata/RHSA-2019:3024
https://access.redhat.com/errata/RHSA-2019:3023
https://access.redhat.com/errata/RHSA-2019:2587
https://access.redhat.com/errata/RHSA-2019:1456
https://access.redhat.com/errata/RHBA-2019:1570
http://www.securityfocus.com/bid/108023
http://www.openwall.com/lists/oss-security/2019/06/03/2
http://seclists.org/fulldisclosure/2019/May/13
http://seclists.org/fulldisclosure/2019/May/11
http://seclists.org/fulldisclosure/2019/May/10
http://packetstormsecurity.com/files/156743/OctoberCMS-Insecure-Dependencies.html
http://packetstormsecurity.com/files/153237/RetireJS-CORS-Issue-Script-Execution.html
http://packetstormsecurity.com/files/152787/dotCMS-5.1.1-Vulnerable-Dependencies.html
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00025.html
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00006.html