Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Prototype Pollution
Vulnerability Description
This affects the package multi-ini before 2.1.2. It is possible to pollute an object's prototype by specifying the constructor.proto object as part of an array. This is a bypass of CVE-2020-28448.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
N/A
Vulnerability Title
Evangelion1204 Multi-ini 资源管理错误漏洞
Vulnerability Description
Evangelion1204 Multi-ini是Evangelion1204个人开发者的一个基于Javascript语言编写的用于Ini配置文件解析的代码库。该代码库支持与Zend文件格式相兼容。 multi-ini 2.1.2之前版本存在安全漏洞,该漏洞源于可以通过指定构造函数来污染对象的原型。原始对象作为数组的一部分。
CVSS Information
N/A
Vulnerability Type
N/A