Description
ini-parser through 0.0.2 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of Object.prototype using a '__proto__' payload.
Remediation
References
https://github.com/rawiroaisen/node-ini-parser/blob/master/index.js#L14
https://snyk.io/vuln/SNYK-JS-INIPARSER-564122
Related Vulnerabilities
CVE-2022-24279 Vulnerability in npm package madlib-object-utils
CVE-2014-3416 Vulnerability in maven package org.jasig.portal:uportal-war
CVE-2017-15089 Vulnerability in maven package org.infinispan:infinispan-commons
CVE-2021-41183 Vulnerability in maven package org.webjars.bower:jquery-ui
CVE-2019-12418 Vulnerability in maven package org.apache.tomcat:tomcat-catalina