PT-2022-8895 · Unknown · Conf-Cfg-Ini

Eugene Lim

·

Published

2022-07-25

·

Updated

2022-08-01

·

CVE-2020-28441

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions conf-cfg-ini versions prior to 1.2.2
Description The issue arises when an attacker submits a malicious INI file to an application that parses it with decode, resulting in prototype pollution on the application. This can be exploited further depending on the context.
Recommendations For versions prior to 1.2.2, update to version 1.2.2 or later to resolve the issue. As a temporary workaround, consider restricting the parsing of INI files with decode to minimize the risk of exploitation.

Exploit

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2020-28441
GHSA-M6MG-JVJF-W44X

Affected Products

Conf-Cfg-Ini