Description
ini-parser through 0.0.2 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of Object.prototype using a '__proto__' payload.
Remediation
References
https://github.com/rawiroaisen/node-ini-parser/blob/master/index.js#L14
https://snyk.io/vuln/SNYK-JS-INIPARSER-564122
Related Vulnerabilities
CVE-2020-15232 Vulnerability in maven package org.mapfish.print:print-standalone
CVE-2022-28150 Vulnerability in maven package com.synopsys.jenkinsci:ownership
CVE-2021-21266 Vulnerability in maven package org.openhab.addons.bundles:org.openhab.binding.insteon
CVE-2023-42794 Vulnerability in maven package org.apache.tomcat:tomcat
CVE-2020-28469 Vulnerability in maven package org.webjars.npm:glob-parent