Multi-ini ProjectCVEs & Vulnerabilities
2 CVEs affecting Multi-ini Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
2 CVEs→ All vendors
Most Affected Products
multi-ini 2
CVE-2020-28460HIGH
This affects the package multi-ini before 2.1.2. It is possible to pollute an object's prototype by specifying the constructor.proto object as part of an array. This is a bypass of CVE-2020-28448.
22 Dec 2020
8.1
CVSS
CVE-2020-28448CRITICAL
This affects the package multi-ini before 2.1.1. It is possible to pollute an object's prototype by specifying the proto object as part of an array.
22 Dec 2020
9.8
CVSS
← PrevPage 1 / 1Next →