QID 980158
QID 980158: Nodejs (npm) Security Update for class-validator (GHSA-fj58-h2fr-3pp2)
In TypeStack class-validator 0.10.2, validate() input validation can be bypassed because certain internal attributes can be overwritten via a conflicting name. Even though there is an optional forbidUnknownValues parameter that can be used to reduce the risk of this bypass, this option is not documented and thus most developers configure input validation in the vulnerable default manner. With this vulnerability, attackers can launch SQL Injection or XSS attacks by injecting arbitrary malicious input. NOTE: a software maintainer agrees with the "is not documented" finding but suggests that much of the responsibility for the risk lies in a different product.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
- GHSA-fj58-h2fr-3pp2 -
github.com/advisories/GHSA-fj58-h2fr-3pp2
CVEs related to QID 980158
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-fj58-h2fr-3pp2 | class-validator |
|