CVE-2020-28441
HIGHconf-cfg-ini < 1.2.2 - Prototype Pollution via Malicious INI File Parsing
Title source: llmDescription
This affects the package conf-cfg-ini before 1.2.2. If an attacker submits a malicious INI file to an application that parses it with decode, they will pollute the prototype on the application. This can be exploited further depending on the context.
References (2)
Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://security.snyk.io/vuln/SNYK-JS-CONFCFGINI-1048973
Patch, Third Party Advisory x_refsource_misc
https://github.com/loge5/conf-cfg-ini/commit/3a88a6c52c31eb6c0f033369eed40aa168a636ea
Scores
CVSS v3
7.3
EPSS
0.0097
EPSS Percentile
57.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Details
CWE
CWE-1321
Status
published
Products (2)
conf-cfg-ini_project/conf-cfg-ini
< 1.2.2
npm/conf-cfg-ini
0 - 1.2.2npm
Published
Jul 25, 2022
Tracked Since
Feb 18, 2026