1 results (0.002 seconds)
CVSS: 9.8EPSS: 1%CPEs: 20EXPL: 4

CVE-2020-28472 – Prototype Pollution
https://notcve.org/view.php?id=CVE-2020-28472
19 Jan 2021 — This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0. If an attacker submits a malicious INI file to an application that parses it with loadSharedConfigFiles , they will pollute the prototype on the application. This can be exploited further depending on the context. Esto afecta al paquete @aws-sdk/shared-ini-file-loader versiones anteriores a 1.0.0-rc.9; el paquete aws-sdk versiones anteriores a 2.814.0. Si un atacante envía un archivo INI... • https://github.com/aws/aws-sdk-js-v3/commit/a209082dff913939672bb069964b33aa4c5409a9 •