Uploaded image for project: 'Percona Monitoring and Management'
  1. Percona Monitoring and Management
  2. PMM-5666

CVE-2019-20149: Update kind-of to 6.0.3

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Done
    • Priority: High
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: 1.17.4
    • Component/s: PMM Server, QAN App
    • Labels:
    • Story Points:
      0
    • Sprint:
      Platform Sprint 13
    • Needs QA:
      Yes

      Description

      https://github.com/advisories/GHSA-6c8f-qphg-qjgp

      Vulnerable versions: < 6.0.3
      Patched version: 6.0.3
      ctorName in index.js in kind-of v6.0.2 allows external user input to overwrite certain internal attributes via a conflicting name, as demonstrated by 'constructor':

      {'name':'Symbol'}

      . Hence, a crafted payload can overwrite this builtin attribute to manipulate the type detection result.

        Smart Checklist

          Attachments

            Activity

              People

              Assignee:
              roman.misyurin Roman Misyurin
              Reporter:
              roma.novikov Roma Novikov
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved: