CVE-2019-20149
Summary
| CVE | CVE-2019-20149 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-12-30 19:15:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | ctorName in index.js in kind-of v6.0.2 allows external user input to overwrite certain internal attributes via a conflicting name, as demonstrated by 'constructor': {'name':'Symbol'}. Hence, a crafted payload can overwrite this builtin attribute to manipulate the type detection result. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| type checking · Issue #30 · jonschlinkert/kind-of · GitHub |
MISC |
github.com |
Exploit, Issue Tracking, Third Party Advisory |
| fix type checking vul in ctorName by xiaofen9 · Pull Request #31 · jonschlinkert/kind-of · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 378599 Splunk Enterprise Third Party Package Updates for June (SVD-2023-0613)
- 981569 Nodejs (npm) Security Update for kind-of (GHSA-6c8f-qphg-qjgp)