Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-37603

Опубликовано: 14 окт. 2022
Источник: debian

Описание

A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the url variable in interpolateName.js.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-loader-utilsfixed2.0.4-1package
node-loader-utilsfixed2.0.0-1+deb11u1bullseyepackage
node-loader-utilsnot-affectedbusterpackage

Примечания

  • https://github.com/webpack/loader-utils/issues/213

  • https://github.com/webpack/loader-utils/pull/225

  • https://github.com/webpack/loader-utils/commit/ac09944dfacd7c4497ef692894b09e63e09a5eeb (v2.0.4)

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the url variable in interpolateName.js.

CVSS3: 7.5
redhat
больше 2 лет назад

A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the url variable in interpolateName.js.

CVSS3: 7.5
nvd
больше 2 лет назад

A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the url variable in interpolateName.js.

CVSS3: 7.5
github
больше 2 лет назад

loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS) via url variable

CVSS3: 9.8
redos
12 месяцев назад

Множественные уязвимости opensearch-dashboards