Description
ini-parser through 0.0.2 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of Object.prototype using a '__proto__' payload.
Remediation
References
https://github.com/rawiroaisen/node-ini-parser/blob/master/index.js#L14
https://snyk.io/vuln/SNYK-JS-INIPARSER-564122
Related Vulnerabilities
CVE-2021-24033 Vulnerability in maven package org.webjars.npm:react-dev-utils
CVE-2014-3652 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2017-18355 Vulnerability in npm package rendertron-middleware
CVE-2021-37695 Vulnerability in maven package org.webjars.npm:ckeditor4
CVE-2014-125087 Vulnerability in maven package com.jamesmurty.utils:java-xmlbuilder