PT-2022-8904 · Unknown · Ion-Parser

Eugene Lim

·

Published

2022-07-25

·

Updated

2022-08-01

·

CVE-2020-28462

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ion-parser versions all
Description The issue affects the ion-parser package, where an attacker can submit a malicious INI file to an application that uses the parse function, leading to prototype pollution on the application. This can be further exploited depending on the context.
Recommendations For all versions of ion-parser, consider disabling the parse function until a patch is available to prevent prototype pollution attacks. Restrict the use of ion-parser to minimize the risk of exploitation. Avoid using ion-parser to parse untrusted INI files until the issue is resolved.

Exploit

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2020-28462
GHSA-7VRV-5M2H-RJW9

Affected Products

Ion-Parser