CVE-2020-7788
🟡 Monitoruj
Zanieczyszczenie prototypu w pakiecie ini umożliwia atakującemu dalsze wykorzystanie podatności.
CVSS
7.3
EPSS
3.6%
Exploit
poc
Vendor
debian
Opis źródłowy (NVD)
This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 3.6% |
| Opublikowano (NVD) | 2020-12-11 11:15:11 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 22:17:03 UTC |
Referencje
- https://github.com/npm/ini/commit/56d2805e07ccd94e2ba0984ac9240ff02d44b6f1 ([email protected]) [Patch, Third Party Advisory]
- https://lists.debian.org/debian-lts-announce/2020/12/msg00032.html ([email protected]) [Mailing List, Third Party Advisory]
- https://snyk.io/vuln/SNYK-JS-INI-1048974 ([email protected]) [Exploit, Third Party Advisory]