Junglewise Threat Intelligence

CVE-2020-28461: js-ini prototype pollution via malicious INI files

CVE-2020-28461 · Severity: low · CVSS 3.1 · Published 2022-07-26

Vendors: npm.

Executive brief

js-ini is a JavaScript library for parsing INI configuration files. A flaw in the parser allows attackers to inject properties into the JavaScript prototype chain by submitting crafted INI files, potentially leading to code execution or application behavior manipulation depending on how the parsed data is used downstream.

Technical details

This is a prototype pollution vulnerability (CWE-1321) in js-ini versions before 1.3.0. When the `parse()` function processes a malicious INI file, it fails to sanitize property keys, allowing an attacker to inject properties into Object.prototype or other built-in prototypes. The vulnerability requires only network access to submit a malicious INI file to an application that uses js-ini's parse function; no authentication or user interaction is required. Successful exploitation allows arbitrary code execution or denial of service depending on the application context. The vulnerability was fixed in version 1.3.0 (commit fa17efb).

Affected products

  • js-ini js-ini before 1.3.0

Timeline

  • 2022-07-26: disclosed
  • 2020-12-22: patched: Fix commit fa17efb; affected versions fixed in 1.3.0

References