Sensitive information sent insecurely In node-kind-of
Description
Validation Bypass in kind-of
Versions of kind-of 6.x prior to 6.0.3 are vulnerable to a Validation Bypass. A maliciously crafted object can alter the result of the type check, allowing attackers to bypass the type checking validation.
Recommendation
Upgrade to versions 6.0.3 or later.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 6.0.3+dfsg-1 | ||
debian 13 | 6.0.3+dfsg-1 | ||
debian 14 | 6.0.3+dfsg-1 | ||
npm | 6.0.3 | ||
debian 12 | 6.0.3+dfsg-1 | ||
rpm rhel8 | - | - |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5.