Junglewise Threat Intelligence

CVE-2020-28472: AWS SDK prototype pollution via shared INI file parsing

CVE-2020-28472 · Severity: low · CVSS 3.1 · Published 2021-11-16

Vendors: npm, Amazon Web Services.

Executive brief

AWS SDK and related libraries parse configuration files (INI format) to load AWS credentials and settings. An attacker can craft a malicious INI file that, when parsed by a vulnerable application, pollutes the JavaScript prototype chain. This can allow an attacker to inject or override properties affecting application behavior, potentially leading to unauthorized access, data manipulation, or service disruption depending on how the application uses the SDK.

Technical details

The vulnerability is a prototype pollution flaw (CWE-1321) in the INI file parsing logic of aws-sdk (versions before 2.814.0) and @aws-sdk/shared-ini-file-loader (versions before 1.0.0-rc.9). When the loadSharedConfigFiles function processes a malicious INI file with crafted profile names (e.g., "__proto__"), it fails to properly sanitize input and pollutes the Object prototype. The attack requires an attacker to control the INI configuration file, either by direct submission or file manipulation. The fix validates profile names and throws an error when they resolve to "__proto__" or other dangerous keys. Patches are available in aws-sdk 2.814.0 and @aws-sdk/shared-ini-file-loader 1.0.0-rc.9.

Affected products

  • Amazon Web Services SDK for JavaScript before 2.814.0
  • Amazon Web Services shared-ini-file-loader before 1.0.0-rc.9

Timeline

  • 2021-01-19: disclosed: CVE-2020-28472 published on NVD
  • 2020-12-18: patched: Fix merged in aws-sdk-js pull request #3585
  • 2021-11-16: advisory: GHSA-rrc9-gqf8-8rwg published

References

Related threats