Advisories for Npm/@Aws-Sdk/Shared-Ini-File-Loader package

2021

Prototype pollution

In aws-sdk/shared-ini-file-loader, if an attacker submits a malicious INI file to an application that parses it with loadSharedConfigFiles, they will pollute the prototype on the application. This can be exploited further depending on the context.