Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22182
HistoryDec 17, 2019 - 2:47 a.m.

Prototype Pollution

2019-12-1702:47:19
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.001 Low

EPSS

Percentile

38.8%

kind-of is vulnerable to prototype pollution. The built-in constructor does not validate or detect type information of user input. If conditions allow, an attacker is able to submit a malicious payload to overwrite the built-in attribute to manipulate the type detection results, and potentially execute arbitrary code.

CPENameOperatorVersion
kind-ofle6.0.2
kind-ofeq6.0.2
kind-ofle6.0.2