VYPR

npm package

conf-cfg-ini

pkg:npm/conf-cfg-ini

Vulnerabilities (1)

  • CVE-2020-28441Jul 25, 2022
    affected < 1.2.2fixed 1.2.2

    This affects the package conf-cfg-ini before 1.2.2. If an attacker submits a malicious INI file to an application that parses it with decode, they will pollute the prototype on the application. This can be exploited further depending on the context.