Junglewise Threat Intelligence

CVE-2020-28441: conf-cfg-ini Prototype Pollution via malicious INI file

CVE-2020-28441 · Severity: low · CVSS 3.1 · Published 2022-07-26

Vendors: npm.

Executive brief

conf-cfg-ini is a Node.js library used to parse INI-format configuration files. A prototype pollution vulnerability in versions before 1.2.2 allows an attacker to craft a malicious INI file that, when parsed by an application, corrupts the JavaScript object prototype. This can lead to unauthorized code execution, data modification, or application crashes depending on how the affected application uses the parsed configuration.

Technical details

This is a prototype pollution vulnerability (CWE-1321) in the conf-cfg-ini NPM package affecting all versions before 1.2.2. The vulnerability exists in the INI file parsing logic, which fails to sanitize object property names when decoding INI files. An attacker can submit a specially crafted INI file containing prototype pollution payloads (e.g., __proto__, constructor, prototype). No authentication or user interaction is required—an application needs only to parse an attacker-controlled INI file using the decode function. The vulnerability was fixed in version 1.2.2 via commits that add validation to prevent pollution of sensitive properties.

Affected products

  • loge5 conf-cfg-ini before 1.2.2

Timeline

  • 2022-07-25: disclosed: Published on NVD
  • 2022-07-26: advisory: GitHub Security Advisory GHSA-m6mg-jvjf-w44x published
  • 2022-07-25: patched: Fixed in version 1.2.2

References