Логотип exploitDog
bind:CVE-2020-28472
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-28472

Количество 2

Количество 2

nvd логотип

CVE-2020-28472

около 5 лет назад

This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0. If an attacker submits a malicious INI file to an application that parses it with loadSharedConfigFiles , they will pollute the prototype on the application. This can be exploited further depending on the context.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-rrc9-gqf8-8rwg

около 4 лет назад

Prototype Pollution via file load in aws-sdk and @aws-sdk/shared-ini-file-loader

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-28472

This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0. If an attacker submits a malicious INI file to an application that parses it with loadSharedConfigFiles , they will pollute the prototype on the application. This can be exploited further depending on the context.

CVSS3: 7.3
2%
Низкий
около 5 лет назад
github логотип
GHSA-rrc9-gqf8-8rwg

Prototype Pollution via file load in aws-sdk and @aws-sdk/shared-ini-file-loader

CVSS3: 7.3
2%
Низкий
около 4 лет назад

Уязвимостей на страницу