PT-2020-17015 · Multi-Ini · Multi-Ini

Huawei

+1

·

Published

2020-12-22

·

Updated

2022-12-02

·

CVE-2020-28460

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions multi-ini versions prior to 2.1.2
Description The issue allows an object's prototype to be polluted by specifying the constructor.proto object as part of an array, effectively bypassing a previous security measure.
Recommendations For versions prior to 2.1.2, update to version 2.1.2 or later to resolve the issue.

Exploit

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2020-28460
GHSA-67MQ-H2R9-RH2M
SNYK-JS-MULTIINI-1053229

Affected Products

Multi-Ini