Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-20149

Опубликовано: 30 дек. 2019
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

ctorName in index.js in kind-of v6.0.2 allows external user input to overwrite certain internal attributes via a conflicting name, as demonstrated by 'constructor': {'name':'Symbol'}. Hence, a crafted payload can overwrite this builtin attribute to manipulate the type detection result.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:kind-of_project:kind-of:6.0.2:*:*:*:*:*:*:*

EPSS

Процентиль: 40%
0.00184
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-668

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

ctorName in index.js in kind-of v6.0.2 allows external user input to overwrite certain internal attributes via a conflicting name, as demonstrated by 'constructor': {'name':'Symbol'}. Hence, a crafted payload can overwrite this builtin attribute to manipulate the type detection result.

CVSS3: 5.9
redhat
около 6 лет назад

ctorName in index.js in kind-of v6.0.2 allows external user input to overwrite certain internal attributes via a conflicting name, as demonstrated by 'constructor': {'name':'Symbol'}. Hence, a crafted payload can overwrite this builtin attribute to manipulate the type detection result.

CVSS3: 7.5
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 7.5
debian
около 6 лет назад

ctorName in index.js in kind-of v6.0.2 allows external user input to o ...

CVSS3: 7.5
github
почти 6 лет назад

Validation Bypass in kind-of

EPSS

Процентиль: 40%
0.00184
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-668