PT-2022-8905 · Unknown+1 · Properties-Reader+1

Eugene Lim

·

Published

2022-07-19

·

Updated

2025-11-18

·

CVE-2020-28471

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions properties-reader versions prior to 2.2.0
Description The issue concerns a prototype pollution vulnerability. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited. Technical details about exploitation are not provided.
Recommendations For versions prior to 2.2.0, update to version 2.2.0 to resolve the issue.

Exploit

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2020-28471
GHSA-JXVF-M3X5-MXWQ

Affected Products

Bitbucket
Properties-Reader