Description
ini-parser through 0.0.2 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of Object.prototype using a '__proto__' payload.
Remediation
References
https://github.com/rawiroaisen/node-ini-parser/blob/master/index.js#L14
https://snyk.io/vuln/SNYK-JS-INIPARSER-564122
Related Vulnerabilities
CVE-2016-3092 Vulnerability in maven package org.apache.tomcat:tomcat-util
CVE-2019-17566 Vulnerability in maven package org.apache.xmlgraphics:batik-transcoder
CVE-2021-4329 Vulnerability in maven package org.webjars.npm:json-logic-js
CVE-2020-1695 Vulnerability in maven package org.jboss.resteasy:resteasy-jaxrs-all