PT-2022-8904 · Unknown · Ion-Parser
Eugene Lim
·
Published
2022-07-25
·
Updated
2022-08-01
·
CVE-2020-28462
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ion-parser versions all
Description
The issue affects the ion-parser package, where an attacker can submit a malicious INI file to an application that uses the
parse function, leading to prototype pollution on the application. This can be further exploited depending on the context.Recommendations
For all versions of ion-parser, consider disabling the
parse function until a patch is available to prevent prototype pollution attacks. Restrict the use of ion-parser to minimize the risk of exploitation. Avoid using ion-parser to parse untrusted INI files until the issue is resolved.Exploit
Fix
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ion-Parser