Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-7788

Опубликовано: 08 дек. 2020
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.

A flaw was found in nodejs-ini. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.

Отчет

Node.JS packages in Red Hat Enterprise Linux and Red Hat Software Collections included the vulnerable dependency packaged in "nodejs-npm" component. Processing malicious files using npm could potentially trigger this vulnerability. The "ini" package bundled with npm was not in the library path where it could be included directly in other programs. The nodejs-nodemon packages in Red Hat Enterprise Linux and Red Hat Software Collections are affected by this vulnerability as they bundle the nodejs-ini library. Usage of that library is governed by nodemon itself, so applications started by nodemon are not impacted. Further, nodemon is a developer tool not intended to be used in production. The ini package is included in Red Hat Quay by protractor and webpack-cli, both of which are dev dependencies.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 9nodejsNot affected
Red Hat Quay 3yarnpkg-iniNot affected
Red Hat Software Collectionsrh-nodejs10-nodejs-nodemonOut of support scope
Red Hat Enterprise Linux 8nodejsFixedRHSA-2021:054816.02.2021
Red Hat Enterprise Linux 8nodejsFixedRHSA-2021:054916.02.2021
Red Hat Enterprise Linux 8nodejsFixedRHSA-2021:055116.02.2021
Red Hat Enterprise Linux 8nodejsFixedRHSA-2021:517116.12.2021
Red Hat Enterprise Linux 8nodejsFixedRHSA-2022:035001.02.2022
Red Hat Enterprise Linux 8.4 Extended Update SupportnodejsFixedRHSA-2022:024625.01.2022
Red Hat Enterprise Linux 9nodejs-nodemonFixedRHSA-2022:659520.09.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1907444nodejs-ini: Prototype pollution via malicious INI file

EPSS

Процентиль: 52%
0.00291
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
больше 4 лет назад

This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.

CVSS3: 7.3
nvd
больше 4 лет назад

This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.

CVSS3: 7.3
debian
больше 4 лет назад

This affects the package ini before 1.3.6. If an attacker submits a ma ...

CVSS3: 7.3
github
больше 4 лет назад

ini before 1.3.6 vulnerable to Prototype Pollution via ini.parse

CVSS3: 7.3
fstec
около 4 лет назад

Уязвимость библиотеки ini прикладного программного обеспечения Аврора Центр, связанная с неконтролируемым изменением атрибутов прототипа объекта, позволяющая нарушителю реализовать атаку типа «загрязнение прототипа»

EPSS

Процентиль: 52%
0.00291
Низкий

7.3 High

CVSS3