Lucene search

K
osvGoogleOSV:CVE-2020-7788
HistoryDec 11, 2020 - 11:15 a.m.

CVE-2020-7788

2020-12-1111:15:11
Google
osv.dev
6

9.4 High

AI Score

Confidence

High

0.012 Low

EPSS

Percentile

85.4%

This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.

Rows per page:
1-10 of 151