9.8

CVE-2020-28472

Exploit

Prototype Pollution

This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0. If an attacker submits a malicious INI file to an application that parses it with loadSharedConfigFiles , they will pollute the prototype on the application. This can be exploited further depending on the context.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Amazon ≫ Aws Sdk For Javascipt SwPlatform node.js Version < 2.814.0
Amazon ≫ Aws Shared Configuration File Loader Version 1.0.0 Update alpha1 SwPlatform node.js
Amazon ≫ Aws Shared Configuration File Loader Version 1.0.0 Update alpha2 SwPlatform node.js
Amazon ≫ Aws Shared Configuration File Loader Version 1.0.0 Update alpha3 SwPlatform node.js
Amazon ≫ Aws Shared Configuration File Loader Version 1.0.0 Update beta1 SwPlatform node.js
Amazon ≫ Aws Shared Configuration File Loader Version 1.0.0 Update beta2 SwPlatform node.js
Amazon ≫ Aws Shared Configuration File Loader Version 1.0.0 Update beta3 SwPlatform node.js
Amazon ≫ Aws Shared Configuration File Loader Version 1.0.0 Update beta4 SwPlatform node.js
Amazon ≫ Aws Shared Configuration File Loader Version 1.0.0 Update gamma1 SwPlatform node.js
Amazon ≫ Aws Shared Configuration File Loader Version 1.0.0 Update gamma2 SwPlatform node.js
Amazon ≫ Aws Shared Configuration File Loader Version 1.0.0 Update gamma3 SwPlatform node.js
Amazon ≫ Aws Shared Configuration File Loader Version 1.0.0 Update gamma4 SwPlatform node.js
Amazon ≫ Aws Shared Configuration File Loader Version 1.0.0 Update gamma5 SwPlatform node.js
Amazon ≫ Aws Shared Configuration File Loader Version 1.0.0 Update gamma6 SwPlatform node.js
Amazon ≫ Aws Shared Configuration File Loader Version 1.0.0 Update gamma7 SwPlatform node.js
Amazon ≫ Aws Shared Configuration File Loader Version 1.0.0 Update gamma8 SwPlatform node.js
Amazon ≫ Aws Shared Configuration File Loader Version 1.0.0 Update rc1 SwPlatform node.js
Amazon ≫ Aws Shared Configuration File Loader Version 1.0.0 Update rc2 SwPlatform node.js
Amazon ≫ Aws Shared Configuration File Loader Version 1.0.0 Update rc3 SwPlatform node.js
Amazon ≫ Aws Shared Configuration File Loader Version 1.0.0 Update rc8 SwPlatform node.js
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.14% 0.797
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Snyk 7.3 3.9 3.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://github.com/aws/aws-sdk-js-v3/commit/a209082dff913939672bb069964b33aa4c5409a9
Patch
Third Party Advisory
https://github.com/aws/aws-sdk-js/pull/3585/commits/7d72aff2a941173733fcb6741b104cd83d3bc611
Patch
Third Party Advisory
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1059426
Third Party Advisory
Exploit
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1059425
Third Party Advisory
Exploit
https://snyk.io/vuln/SNYK-JS-AWSSDK-1059424
Third Party Advisory
Exploit
https://snyk.io/vuln/SNYK-JS-AWSSDKSHAREDINIFILELOADER-1049304
Third Party Advisory
Exploit