Описание
In webpack-subresource-integrity before version 1.5.1, all dynamically loaded chunks receive an invalid integrity hash that is ignored by the browser, and therefore the browser cannot validate their integrity. This removes the additional level of protection offered by SRI for such chunks. Top-level chunks are unaffected. This issue is patched in version 1.5.1.
Ссылки
- PatchThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.5.1 (исключая)
cpe:2.3:a:webpack-subresource-integrity_project:webpack-subresource-integrity:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 37%
0.00159
Низкий
3.7 Low
CVSS3
3.7 Low
CVSS3
5 Medium
CVSS2
Дефекты
CWE-345
CWE-345
Связанные уязвимости
EPSS
Процентиль: 37%
0.00159
Низкий
3.7 Low
CVSS3
3.7 Low
CVSS3
5 Medium
CVSS2
Дефекты
CWE-345
CWE-345