CVE-2019-18413
Summary
| CVE | CVE-2019-18413 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-10-24 18:15:00 UTC |
| Updated | 2023-02-28 15:10:00 UTC |
| Description | In TypeStack class-validator 0.10.2, validate() input validation can be bypassed because certain internal attributes can be overwritten via a conflicting name. Even though there is an optional forbidUnknownValues parameter that can be used to reduce the risk of this bypass, this option is not documented and thus most developers configure input validation in the vulnerable default manner. With this vulnerability, attackers can launch SQL Injection or XSS attacks by injecting arbitrary malicious input. NOTE: a software maintainer agrees with the "is not documented" finding but suggests that much of the responsibility for the risk lies in a different product. |
Risk And Classification
Problem Types: CWE-79 | CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Typestack Class-validator Project | Typestack Class-validator | 0.10.2 | All | All | All |
| Application | Typestack Class-validator Project | Typestack Class-validator | 0.10.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GitHub - typestack/class-validator: Validation made easy using TypeScript decorators. | MISC | github.com | |
| class-validator arbitrary bypass vulnerability · Issue #438 · typestack/class-validator · GitHub | MISC | github.com | |
| class-validator arbitrary bypass vulnerability · Issue #438 · typestack/class-validator · GitHub | MISC | github.com | Exploit, Issue Tracking, Third Party Advisory |
| security: SNYK-JS-CLASSVALIDATOR-1730566 · Issue #1422 · typestack/class-validator · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 980158 Nodejs (npm) Security Update for class-validator (GHSA-fj58-h2fr-3pp2)