Description
ctorName in index.js in kind-of v6.0.2 allows external user input to overwrite certain internal attributes via a conflicting name, as demonstrated by 'constructor': {'name':'Symbol'}. Hence, a crafted payload can overwrite this builtin attribute to manipulate the type detection result.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-0335 | ctorName in index.js in kind-of v6.0.2 allows external user input to overwrite certain internal attributes via a conflicting name, as demonstrated by 'constructor': {'name':'Symbol'}. Hence, a crafted payload can overwrite this builtin attribute to manipulate the type detection result. |
Github GHSA |
GHSA-6c8f-qphg-qjgp | Validation Bypass in kind-of |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T02:39:08.099Z
Reserved: 2019-12-30T00:00:00.000Z
Link: CVE-2019-20149
No data.
Status : Modified
Published: 2019-12-30T19:15:11.910
Modified: 2024-11-21T04:38:06.457
Link: CVE-2019-20149
OpenCVE Enrichment
No data.
EUVD
Github GHSA