Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-28154

Опубликовано: 13 мар. 2023
Источник: debian
EPSS Низкий

Описание

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-webpackfixed5.76.1+dfsg1+~cs17.16.16-1package
node-webpackfixed5.75.0+dfsg+~cs17.16.14-1+deb12u1bookwormpackage
node-webpackfixed4.43.0-6+deb11u1bullseyepackage
node-webpacknot-affectedbusterpackage

Примечания

  • https://github.com/webpack/webpack/pull/16500

  • Merge commit: https://github.com/webpack/webpack/commit/4b4ca3bb53f36a5b8fc6bc1bd976ed7af161bd80 (v5.76.0)

EPSS

Процентиль: 80%
0.01485
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 2 лет назад

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.

CVSS3: 9.1
redhat
больше 2 лет назад

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.

CVSS3: 9.8
nvd
больше 2 лет назад

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.

CVSS3: 9.8
github
больше 2 лет назад

Cross-realm object access in Webpack 5

oracle-oval
больше 2 лет назад

ELSA-2023-12235: pcs security update (IMPORTANT)

EPSS

Процентиль: 80%
0.01485
Низкий