MGASA-2021-0068

Source
https://advisories.mageia.org/MGASA-2021-0068.html
Import Source
https://advisories.mageia.org/MGASA-2021-0068.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2021-0068
Related
Published
2021-02-05T11:54:53Z
Modified
2021-02-05T10:55:46Z
Summary
Updated nodejs-ini package fixes a security vulnerability
Details

It was discovered that there was an issue in nodejs-ini, where an application could be exploited by a malicious input file. This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context (CVE-2020-7788).

References
Credits

Affected packages

Mageia:7 / nodejs-ini

Package

Name
nodejs-ini
Purl
pkg:rpm/mageia/nodejs-ini?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.8-1.mga7

Ecosystem specific

{
    "section": "core"
}