Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-37601

Опубликовано: 12 окт. 2022
Источник: debian

Описание

Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-loader-utilsfixed2.0.3-1package
node-loader-utilsfixed2.0.0-1+deb11u1bullseyepackage

Примечания

  • https://github.com/webpack/loader-utils/issues/212

  • https://github.com/webpack/loader-utils/commit/a93cf6f4702012030f6b5ee8340d5c95ec1c7d4c (v2.0.3)

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 2 лет назад

Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.

CVSS3: 8.1
redhat
больше 2 лет назад

Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.

CVSS3: 9.8
nvd
больше 2 лет назад

Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.

CVSS3: 9.8
msrc
около 2 лет назад

Описание отсутствует

CVSS3: 9.8
github
больше 2 лет назад

Prototype pollution in webpack loader-utils