CVE-2020-28460

CVE-2020-28460

This affects the package multi-ini before 2.1.2. It is possible to pollute an object’s prototype by specifying the constructor.proto object as part of an array. This is a bypass of CVE-2020-28448.

Source: CVE-2020-28460

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다