Exposure of Resource to Wrong Sphere in Kind-of - CVE-2019-20149
Published: August 2, 2023
Vulnerability details
The vulnerability allows a remote attacker to modify files on the system.
The vulnerability exists due to ctorName in index.js in kind-of allows external user input to overwrite certain internal attributes via a conflicting name. A remote unauthenticated attacker can send a specially crafted payload to overwrite builtin attribute and manipulate the type detection result.
Affected software
Cloud Pak for Security (CP4S)
Crowd Server
Crowd Data Center
Red Hat Advanced Cluster Management for Kubernetes
IBM Watson Machine Learning Accelerator
How to mitigate CVE-2019-20149
Cloud Pak for Security (CP4S) - update to 1.10.13.0
Crowd Server - update to 7.1.3
Crowd Data Center - update to 7.1.3
Red Hat Advanced Cluster Management for Kubernetes - update to 2.3.2