Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-37599

Опубликовано: 11 окт. 2022
Источник: debian
EPSS Низкий

Описание

A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-loader-utilsfixed2.0.4-1package
node-loader-utilsfixed2.0.0-1+deb11u1bullseyepackage
node-loader-utilsnot-affectedbusterpackage

Примечания

  • https://github.com/webpack/loader-utils/issues/211

  • https://github.com/webpack/loader-utils/pull/225

  • https://github.com/webpack/loader-utils/commit/ac09944dfacd7c4497ef692894b09e63e09a5eeb (v2.0.4)

EPSS

Процентиль: 87%
0.03427
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js.

CVSS3: 7.5
redhat
больше 2 лет назад

A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js.

CVSS3: 7.5
nvd
больше 2 лет назад

A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js.

CVSS3: 7.5
github
больше 2 лет назад

loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS)

CVSS3: 9.8
redos
12 месяцев назад

Множественные уязвимости opensearch-dashboards

EPSS

Процентиль: 87%
0.03427
Низкий