Junglewise Threat Intelligence

CVE-2019-10805: valib internal property tampering in validation functions

CVE-2019-10805 · Severity: low · CVSS 3.1 · Published 2021-04-13

Vendors: npm.

Executive brief

valib is a JavaScript validation library used to check and validate data structures in applications. This vulnerability allows an attacker to craft malicious objects that bypass the library's security checks by overwriting built-in functions, potentially allowing invalid or dangerous data to pass validation and reach application logic.

Technical details

valib through version 2.0.0 is vulnerable to internal property tampering due to unsafe use of the hasOwnProperty function during object inspection. The library directly invokes hasOwnProperty from user-supplied objects without proper safeguards, allowing an attacker to override this built-in function to return false for all properties. This manipulation bypasses inspection functions like isEmpty(), countKeys(), and hasValue(), enabling malicious data to circumvent validation checks. The attack requires no authentication or user interaction and is exploitable over the network. No patched version is currently available; the project appears to be unmaintained.

Affected products

  • valib valib through 2.0.0

Timeline

  • 2020-02-28: disclosed
  • 2021-04-13: advisory

References