nodejs-kind-of: ctorName in index.js allows external user input to overwrite certain internal attributes
Published Dec 30, 2019
7.5
HIGHCVSS 3.1
EPSS 2.34%
Description
ctorName in index.js in kind-of v6.0.2 allows external user input to overwrite certain internal attributes via a conflicting name, as demonstrated by 'constructor': {'name':'Symbol'}. Hence, a crafted payload can overwrite this builtin attribute to manipulate the type detection result.
Affected products
No data.
- 6.0.2
No data.
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8
rhacm2/kui-web-terminal-rhel8:v2.3.2-5
Fixed · RHSA-2021:3454
Logging Subsystem for Red Hat OpenShift
openshift-logging/kibana6-rhel8
Will not fix
OpenShift Service Mesh 2.0
servicemesh-grafana
Affected
OpenShift Service Mesh 2.0
servicemesh-prometheus
Affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/application-ui-rhel8
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/console-api-rhel8
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/console-header-rhel8
Will not fix
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/console-rhel8
Fix deferred
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/console-ui-rhel8
Will not fix
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/grc-ui-api-rhel8
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/grc-ui-rhel8
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/mcm-topology-api-rhel8
Will not fix
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/mcm-topology-rhel8
Will not fix
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/search-api-rhel8
Fix deferred
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/search-ui-rhel8
Fix deferred
Red Hat Advanced Cluster Security 3
advanced-cluster-security/rhacs-main-rhel8
Fix deferred
Red Hat Ansible Automation Platform 1.2
kind-of
Fix deferred
Red Hat Ceph Storage 4
rhceph/rhceph-4-dashboard-rhel8
Will not fix
Red Hat Enterprise Linux 8
nodejs:10/nodejs-nodemon
Out of support scope
Red Hat OpenShift Container Platform 3.11
kibana
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/ose-grafana
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/ose-logging-kibana6
Out of support scope
Red Hat OpenShift Container Platform 4
openshift4/ose-prometheus
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/ose-thanos-rhel8
Will not fix
Red Hat OpenShift distributed tracing 2
rhosdt/jaeger-all-in-one-rhel8
Fix deferred
Red Hat Openshift Data Foundation 4
odf4/mcg-core-rhel8
Not affected
Red Hat Openshift Data Foundation 4
odf4/odf-console-rhel9
Fix deferred
Red Hat Quay 3
quay/quay-rhel8
Affected
Red Hat Software Collections
rh-nodejs10-nodejs-nodemon
Out of support scope
Red Hat Virtualization 4
cockpit-ovirt
Not affected
Red Hat Virtualization 4
ovirt-engine-ui-extensions
Not affected
Red Hat Virtualization 4
ovirt-web-ui
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 | rhacm2/kui-web-terminal-rhel8:v2.3.2-5 | Fixed | RHSA-2021:3454 |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/kibana6-rhel8 | Will not fix | n/a |
| OpenShift Service Mesh 2.0 | servicemesh-grafana | Affected | n/a |
| OpenShift Service Mesh 2.0 | servicemesh-prometheus | Affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/application-ui-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/console-api-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/console-header-rhel8 | Will not fix | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/console-rhel8 | Fix deferred | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/console-ui-rhel8 | Will not fix | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/grc-ui-api-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/grc-ui-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/mcm-topology-api-rhel8 | Will not fix | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/mcm-topology-rhel8 | Will not fix | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/search-api-rhel8 | Fix deferred | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/search-ui-rhel8 | Fix deferred | n/a |
| Red Hat Advanced Cluster Security 3 | advanced-cluster-security/rhacs-main-rhel8 | Fix deferred | n/a |
| Red Hat Ansible Automation Platform 1.2 | kind-of | Fix deferred | n/a |
| Red Hat Ceph Storage 4 | rhceph/rhceph-4-dashboard-rhel8 | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | nodejs:10/nodejs-nodemon | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.11 | kibana | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-grafana | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-logging-kibana6 | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-prometheus | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-thanos-rhel8 | Will not fix | n/a |
| Red Hat OpenShift distributed tracing 2 | rhosdt/jaeger-all-in-one-rhel8 | Fix deferred | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/mcg-core-rhel8 | Not affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/odf-console-rhel9 | Fix deferred | n/a |
| Red Hat Quay 3 | quay/quay-rhel8 | Affected | n/a |
| Red Hat Software Collections | rh-nodejs10-nodejs-nodemon | Out of support scope | n/a |
| Red Hat Virtualization 4 | cockpit-ovirt | Not affected | n/a |
| Red Hat Virtualization 4 | ovirt-engine-ui-extensions | Not affected | n/a |
| Red Hat Virtualization 4 | ovirt-web-ui | Not affected | n/a |
kind-of
npm
Introduced 6.0.0 Fixed 6.0.3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | kind-of | 6.0.0 | 6.0.3 |
Remediation
Red Hat statement
While some components do package a vulnerable version of `kind-of`, access to them requires OpenShift OAuth credentials and hence have been marked with a Low impact. This applies to the following products: - OpenShift ServiceMesh (OSSM) - Red Hat Advanced Cluster Management for Kubernetes (RHACM) - OpenShift distributed tracing - OpenShift Data Foundation In Openshift Container Platform (OCP) 4.6 the openshift4/ose-logging-kibana container delivers a vulnerable version of `kind-of`, however OCP 4.6 is Out Of Support Scope (OOSS) for Moderate and Low impact vulnerabilities. Since the release of OCP 4.7 this component is now delivered as part of the OpenShift Logging product (openshift-logging/kibana6-rhel8 container). Further, OCP 3.11 has been set to Will not fix, as OCP 3.11 is moving into maintenance phase of support. In Red Hat Virtualization some components do package a version of `kind-of`, however none use an affected version (later than 6.0.0, prior to 6.0.3)
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.34% (0.02342) | 83.01th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.28% (0.02278) | 80.78th | v5 (v2026.06.15) |
| Mar 30, 2025 | 0.83% (0.00829) | 72.34th | v4 (v2025.03.14) |
| Mar 29, 2025 | 2.28% (0.02283) | 74.44th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.83% (0.00829) | 72.87th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.09% (0.00091) | 40.39th | v3 (v2023.03.01) |
| Jul 17, 2024 | 0.09% (0.00091) | 39.14th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.09% (0.00091) | 37.11th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.50% (0.04499) | 88.81th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.50% (0.04499) | 74.08th | v2 (v2022.01.01) |
| Feb 3, 2022 | 2.74% (0.02742) | 63.06th | v5 (v2026.06.15) |
| Apr 14, 2021 | 2.74% (0.02742) | 0.00th | v1 |
References (10)
- https://access.redhat.com/security/cve/CVE-2019-20149 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1959721 Issue Tracking
- https://github.com/advisories/GHSA-6c8f-qphg-qjgp Advisory
- https://github.com/jonschlinkert/kind-of/commit/1df992ce6d5a1292048e5fe9c52c5382f941ee0b
- https://github.com/jonschlinkert/kind-of/issues/30 x_refsource_MISCExploitIssue TrackingThird Party Advisory
- https://github.com/jonschlinkert/kind-of/pull/31 x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-20149
- https://snyk.io/vuln/SNYK-JS-KINDOF-537849
- https://www.cve.org/CVERecord?id=CVE-2019-20149
- https://www.npmjs.com/advisories/1490
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-20149 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1959721 | Issue Tracking | |
| https://github.com/advisories/GHSA-6c8f-qphg-qjgp | Advisory | |
| https://github.com/jonschlinkert/kind-of/commit/1df992ce6d5a1292048e5fe9c52c5382f941ee0b | ||
| https://github.com/jonschlinkert/kind-of/issues/30 | x_refsource_MISCExploitIssue TrackingThird Party Advisory | |
| https://github.com/jonschlinkert/kind-of/pull/31 | x_refsource_MISCPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-20149 | ||
| https://snyk.io/vuln/SNYK-JS-KINDOF-537849 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-20149 | ||
| https://www.npmjs.com/advisories/1490 |
Change history (0)
No recorded changes yet.