9.8

CVE-2020-28472

Exploit

This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0. If an attacker submits a malicious INI file to an application that parses it with loadSharedConfigFiles , they will pollute the prototype on the application. This can be exploited further depending on the context.

Data is provided by the National Vulnerability Database (NVD)
AmazonAws Sdk For Javascipt SwPlatformnode.js Version < 2.814.0
AmazonAws Shared Configuration File Loader Version1.0.0 Updatealpha1 SwPlatformnode.js
AmazonAws Shared Configuration File Loader Version1.0.0 Updatealpha2 SwPlatformnode.js
AmazonAws Shared Configuration File Loader Version1.0.0 Updatealpha3 SwPlatformnode.js
AmazonAws Shared Configuration File Loader Version1.0.0 Updatebeta1 SwPlatformnode.js
AmazonAws Shared Configuration File Loader Version1.0.0 Updatebeta2 SwPlatformnode.js
AmazonAws Shared Configuration File Loader Version1.0.0 Updatebeta3 SwPlatformnode.js
AmazonAws Shared Configuration File Loader Version1.0.0 Updatebeta4 SwPlatformnode.js
AmazonAws Shared Configuration File Loader Version1.0.0 Updategamma1 SwPlatformnode.js
AmazonAws Shared Configuration File Loader Version1.0.0 Updategamma2 SwPlatformnode.js
AmazonAws Shared Configuration File Loader Version1.0.0 Updategamma3 SwPlatformnode.js
AmazonAws Shared Configuration File Loader Version1.0.0 Updategamma4 SwPlatformnode.js
AmazonAws Shared Configuration File Loader Version1.0.0 Updategamma5 SwPlatformnode.js
AmazonAws Shared Configuration File Loader Version1.0.0 Updategamma6 SwPlatformnode.js
AmazonAws Shared Configuration File Loader Version1.0.0 Updategamma7 SwPlatformnode.js
AmazonAws Shared Configuration File Loader Version1.0.0 Updategamma8 SwPlatformnode.js
AmazonAws Shared Configuration File Loader Version1.0.0 Updaterc1 SwPlatformnode.js
AmazonAws Shared Configuration File Loader Version1.0.0 Updaterc2 SwPlatformnode.js
AmazonAws Shared Configuration File Loader Version1.0.0 Updaterc3 SwPlatformnode.js
AmazonAws Shared Configuration File Loader Version1.0.0 Updaterc8 SwPlatformnode.js
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.66% 0.803
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
report@snyk.io 7.3 3.9 3.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L