We found results for “”
CVE-2019-20149
Good to know:
Date: December 30, 2019
ctorName in index.js in kind-of v6.0.2 allows external user input to overwrite certain internal attributes via a conflicting name, as demonstrated by 'constructor': {'name':'Symbol'}. Hence, a crafted payload can overwrite this builtin attribute to manipulate the type detection result.
Language: JS
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Top Fix
Upgrade Version
Upgrade to version trezebits/trezevel-gallery - no_fix;scancode/portal-module - dev-dependabot/npm_and_yarn/Resources/assets/coreui/path-parse-1.0.7;scancode/portal-module - dev-dependabot/npm_and_yarn/Resources/assets/coreui/decode-uri-component-0.2.2;scancode/portal-module - v1.0.12;postboxcms/postbox - dev-dependabot/npm_and_yarn/browserslist-4.16.6;postboxcms/postbox - dev-dependabot/npm_and_yarn/url-parse-1.5.10;postboxcms/postbox - dev-dependabot/npm_and_yarn/ws-6.2.2;postboxcms/postbox - dev-sanketraut-patch-1;postboxcms/postbox - dev-feature/ISSUE-39;postboxcms/postbox - dev-package/dbo;moxie-dom - 0.1.1-alpha.0;timoetting/kirby-builder - v2.0.0;timoetting/kirby-builder - v2.0.2;timoetting/kirby-builder - v2.0.3;Virteom.Tenant.Mobile.Framework.Android - 0.20.41.103-prerelease;chrisbraybrooke/laravel-ecommerce - 0.0.11;chrisbraybrooke/laravel-ecommerce - 0.0.56;chrisbraybrooke/laravel-ecommerce - dev-form-field-key;Virteom.Tenant.Mobile.Framework.UWP - 0.20.41.103-prerelease;Indianadavy.VueJsWebAPITemplate.CSharp - 1.0.1;BasicBackEndTemplate - no_fix;Virteom.Tenant.Mobile.Bluetooth.Android - 0.20.41.103-prerelease;computerundsound/curserver - 2.2.0;computerundsound/curserver - no_fix;CoreVueWebTest - 3.0.101;greenpeace/planet4-child-theme-storytelling - v0.9.7;greenpeace/planet4-child-theme-storytelling - v0.12;greenpeace/planet4-child-theme-storytelling - dev-old-ui;rustimate-client - no_fix;BumperLane.Public.Service.Contracts - 0.23.35.214-prerelease;humanmade/workflows - dev-master;humanmade/workflows - 0.4.8-rc.1;Virteom.Public.Utilities - 0.23.37.212-prerelease;zymawy/ironside-core - dev-utils;Virteom.Tenant.Mobile.Framework.iOS - 0.20.41.103-prerelease;Virteom.Tenant.Mobile.Framework - 0.21.29.159-prerelease;bizprove/canvas - v1.0;BumperLane.Public.Api.Client - 0.23.35.214-prerelease;Virteom.Tenant.Mobile.Bluetooth.iOS - 0.20.41.103-prerelease;gheb/nn - dev-master;BasicBackEndIdentityTemplate - no_fix;seidemann-web/wave-theme - dev-omage-theme;PWPTemplateCMS - no_fix;genenotebook - 0.3.0;anhredweb/redshop-base - 1.0.1;flexxia/flexprimeng - dev-update-angularjs;flexxia/flexprimeng - dev-dependabot/npm_and_yarn/css/postcss/y18n-3.2.2;cloudscribe.templates - 5.2.0;mayronalves/laravel-core - dev-dependabot/composer/symfony/mime-4.4.1;adamstyperek/base.symfony.crud - no_fix;Virteom.Tenant.Mobile.Bluetooth - 0.21.29.159-prerelease;ShowingVault.DotNet.Sdk - 0.13.41.190-prerelease;sergiosgc/jsonschema-form - dev-dependabot/npm_and_yarn/js/elliptic-6.5.3;sergiosgc/jsonschema-form - dev-dependabot/npm_and_yarn/js/webpack-5.94.0;sergiosgc/jsonschema-form - no_fix;angellco/spoon - 3.2.5;kind-of - 6.0.3;oxid-esales/wave-theme - dev-oxscript-google-analytics;BumperLane.Public.Api.V2.ClientModule - 0.23.35.214-prerelease;pwptemplatepusintek - no_fix;jupyterlab-nvdashboard - 0.3.0;mmi/mmi-cms - 2.3.1;Umbraco.Iconator - no_fix;doublesecretagency/craft-spoon - 3.2.5;mia3/coding-standard - no_fix;GR.PageRender.Razor - 1.8.0;org.webjars.npm:kind-of:6.0.3
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | HIGH |
| Availability (A): | NONE |
CVSS v2
| Base Score: |
|
|---|---|
| Access Vector (AV): | NETWORK |
| Access Complexity (AC): | LOW |
| Authentication (AU): | NONE |
| Confidentiality (C): | NONE |
| Integrity (I): | PARTIAL |
| Availability (A): | NONE |
| Additional information: |
Vulnerabilities
Projects
Contact Us


