Description
ini-parser through 0.0.2 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of Object.prototype using a '__proto__' payload.
Remediation
References
https://github.com/rawiroaisen/node-ini-parser/blob/master/index.js#L14
https://snyk.io/vuln/SNYK-JS-INIPARSER-564122
Related Vulnerabilities
CVE-2022-36079 Vulnerability in npm package parse-server
CVE-2023-35151 Vulnerability in maven package org.xwiki.platform:xwiki-platform-rest-server
CVE-2021-23624 Vulnerability in npm package dotty
CVE-2021-30246 Vulnerability in maven package org.webjars.bowergithub.kjur:jsrsasign
CVE-2014-7810 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-el