Description
ini-parser through 0.0.2 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of Object.prototype using a '__proto__' payload.
Remediation
References
https://snyk.io/vuln/SNYK-JS-INIPARSER-564122
https://github.com/rawiroaisen/node-ini-parser/blob/master/index.js#L14
Related Vulnerabilities
CVE-2019-15599 Vulnerability in maven package org.webjars.npm:tree-kill
CVE-2019-20922 Vulnerability in npm package handlebars
CVE-2018-14380 Vulnerability in npm package graylog-web-interface
CVE-2019-6284 Vulnerability in npm package node-sass
CVE-2022-36098 Vulnerability in maven package org.xwiki.platform:xwiki-platform-mentions-ui