CVE-2020-28472
Prototype Pollution
Severity Score
9.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
4
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0. If an attacker submits a malicious INI file to an application that parses it with loadSharedConfigFiles , they will pollute the prototype on the application. This can be exploited further depending on the context.
Esto afecta al paquete @aws-sdk/shared-ini-file-loader versiones anteriores a 1.0.0-rc.9; el paquete aws-sdk versiones anteriores a 2.814.0. Si un atacante envía un archivo INI malicioso hacia una aplicación que lo analiza con la función loadSharedConfigFiles, contaminará el prototipo de la aplicación. Esto puede ser explotado aún más dependiendo del contexto
*Credits:
Eugene Lim, Government Technology Agency Cyber Security Group
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2020-11-12 CVE Reserved
- 2021-01-19 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-16 First Exploit
- 2024-10-06 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (6)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1059426 | 2024-09-16 | |
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1059425 | 2024-09-16 | |
https://snyk.io/vuln/SNYK-JS-AWSSDK-1059424 | 2024-09-16 | |
https://snyk.io/vuln/SNYK-JS-AWSSDKSHAREDINIFILELOADER-1049304 | 2024-09-16 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Amazon Search vendor "Amazon" | Aws Sdk For Javascipt Search vendor "Amazon" for product "Aws Sdk For Javascipt" | < 2.814.0 Search vendor "Amazon" for product "Aws Sdk For Javascipt" and version " < 2.814.0" | node.js |
Affected
| ||||||
Amazon Search vendor "Amazon" | Aws Shared Configuration File Loader Search vendor "Amazon" for product "Aws Shared Configuration File Loader" | 1.0.0 Search vendor "Amazon" for product "Aws Shared Configuration File Loader" and version "1.0.0" | alpha1, node.js |
Affected
| ||||||
Amazon Search vendor "Amazon" | Aws Shared Configuration File Loader Search vendor "Amazon" for product "Aws Shared Configuration File Loader" | 1.0.0 Search vendor "Amazon" for product "Aws Shared Configuration File Loader" and version "1.0.0" | alpha2, node.js |
Affected
| ||||||
Amazon Search vendor "Amazon" | Aws Shared Configuration File Loader Search vendor "Amazon" for product "Aws Shared Configuration File Loader" | 1.0.0 Search vendor "Amazon" for product "Aws Shared Configuration File Loader" and version "1.0.0" | alpha3, node.js |
Affected
| ||||||
Amazon Search vendor "Amazon" | Aws Shared Configuration File Loader Search vendor "Amazon" for product "Aws Shared Configuration File Loader" | 1.0.0 Search vendor "Amazon" for product "Aws Shared Configuration File Loader" and version "1.0.0" | beta1, node.js |
Affected
| ||||||
Amazon Search vendor "Amazon" | Aws Shared Configuration File Loader Search vendor "Amazon" for product "Aws Shared Configuration File Loader" | 1.0.0 Search vendor "Amazon" for product "Aws Shared Configuration File Loader" and version "1.0.0" | beta2, node.js |
Affected
| ||||||
Amazon Search vendor "Amazon" | Aws Shared Configuration File Loader Search vendor "Amazon" for product "Aws Shared Configuration File Loader" | 1.0.0 Search vendor "Amazon" for product "Aws Shared Configuration File Loader" and version "1.0.0" | beta3, node.js |
Affected
| ||||||
Amazon Search vendor "Amazon" | Aws Shared Configuration File Loader Search vendor "Amazon" for product "Aws Shared Configuration File Loader" | 1.0.0 Search vendor "Amazon" for product "Aws Shared Configuration File Loader" and version "1.0.0" | beta4, node.js |
Affected
| ||||||
Amazon Search vendor "Amazon" | Aws Shared Configuration File Loader Search vendor "Amazon" for product "Aws Shared Configuration File Loader" | 1.0.0 Search vendor "Amazon" for product "Aws Shared Configuration File Loader" and version "1.0.0" | gamma1, node.js |
Affected
| ||||||
Amazon Search vendor "Amazon" | Aws Shared Configuration File Loader Search vendor "Amazon" for product "Aws Shared Configuration File Loader" | 1.0.0 Search vendor "Amazon" for product "Aws Shared Configuration File Loader" and version "1.0.0" | gamma2, node.js |
Affected
| ||||||
Amazon Search vendor "Amazon" | Aws Shared Configuration File Loader Search vendor "Amazon" for product "Aws Shared Configuration File Loader" | 1.0.0 Search vendor "Amazon" for product "Aws Shared Configuration File Loader" and version "1.0.0" | gamma3, node.js |
Affected
| ||||||
Amazon Search vendor "Amazon" | Aws Shared Configuration File Loader Search vendor "Amazon" for product "Aws Shared Configuration File Loader" | 1.0.0 Search vendor "Amazon" for product "Aws Shared Configuration File Loader" and version "1.0.0" | gamma4, node.js |
Affected
| ||||||
Amazon Search vendor "Amazon" | Aws Shared Configuration File Loader Search vendor "Amazon" for product "Aws Shared Configuration File Loader" | 1.0.0 Search vendor "Amazon" for product "Aws Shared Configuration File Loader" and version "1.0.0" | gamma5, node.js |
Affected
| ||||||
Amazon Search vendor "Amazon" | Aws Shared Configuration File Loader Search vendor "Amazon" for product "Aws Shared Configuration File Loader" | 1.0.0 Search vendor "Amazon" for product "Aws Shared Configuration File Loader" and version "1.0.0" | gamma6, node.js |
Affected
| ||||||
Amazon Search vendor "Amazon" | Aws Shared Configuration File Loader Search vendor "Amazon" for product "Aws Shared Configuration File Loader" | 1.0.0 Search vendor "Amazon" for product "Aws Shared Configuration File Loader" and version "1.0.0" | gamma7, node.js |
Affected
| ||||||
Amazon Search vendor "Amazon" | Aws Shared Configuration File Loader Search vendor "Amazon" for product "Aws Shared Configuration File Loader" | 1.0.0 Search vendor "Amazon" for product "Aws Shared Configuration File Loader" and version "1.0.0" | gamma8, node.js |
Affected
| ||||||
Amazon Search vendor "Amazon" | Aws Shared Configuration File Loader Search vendor "Amazon" for product "Aws Shared Configuration File Loader" | 1.0.0 Search vendor "Amazon" for product "Aws Shared Configuration File Loader" and version "1.0.0" | rc1, node.js |
Affected
| ||||||
Amazon Search vendor "Amazon" | Aws Shared Configuration File Loader Search vendor "Amazon" for product "Aws Shared Configuration File Loader" | 1.0.0 Search vendor "Amazon" for product "Aws Shared Configuration File Loader" and version "1.0.0" | rc2, node.js |
Affected
| ||||||
Amazon Search vendor "Amazon" | Aws Shared Configuration File Loader Search vendor "Amazon" for product "Aws Shared Configuration File Loader" | 1.0.0 Search vendor "Amazon" for product "Aws Shared Configuration File Loader" and version "1.0.0" | rc3, node.js |
Affected
| ||||||
Amazon Search vendor "Amazon" | Aws Shared Configuration File Loader Search vendor "Amazon" for product "Aws Shared Configuration File Loader" | 1.0.0 Search vendor "Amazon" for product "Aws Shared Configuration File Loader" and version "1.0.0" | rc8, node.js |
Affected
|