Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-m6mg-jvjf-w44x: conf-cfg-ini Prototype Pollution via malicious INI file before v1.2.2

This affects the package conf-cfg-ini before 1.2.2. If an attacker submits a malicious INI file to an application that parses it with decode, they will pollute the prototype on the application. This can be exploited further depending on the context.

ghsa
#git

conf-cfg-ini Prototype Pollution via malicious INI file before v1.2.2

Critical severity GitHub Reviewed Published Jul 26, 2022 • Updated Aug 4, 2022

Related news

CVE-2020-28441: fix: prevent prototype pollution attack · loge5/conf-cfg-ini@3a88a6c

This affects the package conf-cfg-ini before 1.2.2. If an attacker submits a malicious INI file to an application that parses it with decode, they will pollute the prototype on the application. This can be exploited further depending on the context.