Prototype Pollution In node-ini
Description
This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 2.0.0-1 | ||
debian 11 | 2.0.0-1 | ||
debian 13 | 2.0.0-1 | ||
debian 14 | 2.0.0-1 | ||
npm | 1.3.6 | ||
rpm rhel9 | 0:2.0.19-1.el9_0 | ||
rpm rhel8 | 1:10.23.1-1.module+el8.3.0+9502+012d8a97 | ||
rpm rhel8.4 | 1:14.18.2-2.module+el8.4.0+13643+6c0ebf22 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2.