Headline
GHSA-m6mg-jvjf-w44x: conf-cfg-ini Prototype Pollution via malicious INI file before v1.2.2
This affects the package conf-cfg-ini before 1.2.2. If an attacker submits a malicious INI file to an application that parses it with decode, they will pollute the prototype on the application. This can be exploited further depending on the context.
conf-cfg-ini Prototype Pollution via malicious INI file before v1.2.2
Critical severity GitHub Reviewed Published Jul 26, 2022 • Updated Aug 4, 2022
Related news
CVE-2020-28441: fix: prevent prototype pollution attack · loge5/conf-cfg-ini@3a88a6c
This affects the package conf-cfg-ini before 1.2.2. If an attacker submits a malicious INI file to an application that parses it with decode, they will pollute the prototype on the application. This can be exploited further depending on the context.