Description
This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.
Remediation
References
https://github.com/npm/ini/commit/56d2805e07ccd94e2ba0984ac9240ff02d44b6f1
https://lists.debian.org/debian-lts-announce/2020/12/msg00032.html
https://snyk.io/vuln/SNYK-JS-INI-1048974
Related Vulnerabilities
CVE-2023-25570 Vulnerability in maven package com.ctrip.framework.apollo:apollo
CVE-2023-39155 Vulnerability in maven package org.jenkins-ci.plugins:chef-identity
CVE-2022-37257 Vulnerability in npm package steal
CVE-2017-3523 Vulnerability in maven package mysql:mysql-connector-java
CVE-2021-32809 Vulnerability in maven package org.webjars.bowergithub.ckeditor:ckeditor4