CVE-2020-28441: Conf-Cfg-Ini Project Conf-Cfg-Ini
Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.
This affects the package conf-cfg-ini before 1.2.2. If an attacker submits a malicious INI file to an application that parses it with decode, they will pollute the prototype on the application. This can be exploited further depending on the context.
Affected products
- Conf-Cfg-Ini Project Conf-Cfg-Ini: before 1.2.2 (fixed in 1.2.2)
Published 2022-07-25. Last modified 2026-06-17.