CVE-2019-18413 - CVE House
Back to Database
Status published Low CVE-2019-18413

In TypeStack class-validator 0.10.2, validate() input validation can be bypassed...

Vulnerability Description

In TypeStack class-validator 0.10.2, validate() input validation can be bypassed because certain internal attributes can be overwritten via a conflicting name. Even though there is an optional forbidUnknownValues parameter that can be used to reduce the risk of this bypass, this option is not documented and thus most developers configure input validation in the vulnerable default manner. With this vulnerability, attackers can launch SQL Injection or XSS attacks by injecting arbitrary malicious input. NOTE: a software maintainer agrees with the "is not documented" finding but suggests that much of the responsibility for the risk lies in a different product.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-18413

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

typestack class-validator project

View all reports →

Affected Software

typestack class-validator
Vulnerable Versions:
0.10.2

Timeline

Official Publish: October 24th, 2019
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AC:H/AV:N/A:N/C:N/I:L/PR:N/S:U/UI:N

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.