ZeroHour

CVE-2020-28472

PoC ×4
CVSS 3.1
9.8 critical
EPSS
2%p81
Published
()
Modified
Description

This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0. If an attacker submits a malicious INI file to an application that parses it with loadSharedConfigFiles , they will pollute the prototype on the application. This can be exploited further depending on the context.

Vendors
amazon
Products
aws sdk for javascipt, aws shared configuration file loader
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.