Description
ini-parser through 0.0.2 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of Object.prototype using a '__proto__' payload.
Remediation
References
https://github.com/rawiroaisen/node-ini-parser/blob/master/index.js#L14
https://snyk.io/vuln/SNYK-JS-INIPARSER-564122
Related Vulnerabilities
CVE-2021-29418 Vulnerability in npm package netmask
CVE-2020-26302 Vulnerability in maven package org.webjars.npm:is_js
CVE-2023-40350 Vulnerability in maven package org.jenkins-ci.plugins:docker-swarm
CVE-2020-7707 Vulnerability in npm package property-expr
CVE-2021-46708 Vulnerability in maven package org.webjars:swagger-ui