CVE-2020-7788High· 7.3▾ TwilightThis affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the co…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.2 · likelihood 0.7 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
3.7%
This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.
ini < 1.3.6debian_linux = 9.0Upgrade past the affected range:
ini 1.3.6Connected by shared product, vendor, weakness, or advisory.
CVE-2021-23450High· 7.5All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
CVE-2021-23383Medium· 5.6The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.
CVE-2020-5258High· 7.7In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution
CVE-2021-44906Critical· 9.8Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
CVE-2020-7639Medium· 5.3eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.
CVE-2020-7598Medium· 5.6minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.