Описание
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
node-loader-utils | fixed | 2.0.4-1 | package | |
node-loader-utils | fixed | 2.0.0-1+deb11u1 | bullseye | package |
node-loader-utils | not-affected | buster | package |
Примечания
https://github.com/webpack/loader-utils/issues/211
https://github.com/webpack/loader-utils/pull/225
https://github.com/webpack/loader-utils/commit/ac09944dfacd7c4497ef692894b09e63e09a5eeb (v2.0.4)
EPSS
Связанные уязвимости
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js.
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js.
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js.
loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS)
EPSS