OSV 1.4.0 · github-reviewed · 修改于 2022-12-03 11:51
发布时间
2021-04-13 23:23
GitHub 审查时间
2021-04-08 07:23
NVD 发布时间
2020-12-22 21:15
源文件
advisories/github-reviewed/2021/04/GHSA-67mq-h2r9-rh2m/GHSA-67mq-h2r9-rh2m.json
This affects the package multi-ini before 2.1.2. It is possible to pollute an object's prototype by specifying the constructor.proto object as part of an array. This is a bypass of CVE-2020-28448.