Описание
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.
A prototype pollution vulnerability was found in the parseQuery function in parseQuery.js in the webpack loader-utils via the name variable in parseQuery.js. This flaw can lead to a denial of service or remote code execution.
Отчет
Packages shipped in Red Hat Enterprise Linux use 'loader-utils' as a transitive dependency. Thus, reducing the impact to Moderate. In Red Hat containerized products like OCP and ODF, the vulnerable loader-utils NodeJS module is bundled as a transitive dependency, hence the direct impact is reduced to Moderate.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Logging Subsystem for Red Hat OpenShift | openshift-logging/kibana6-rhel8 | Not affected | ||
Migration Toolkit for Virtualization | migration-toolkit-virtualization/mtv-ui-rhel8 | Fix deferred | ||
OpenShift Developer Tools and Services | odo | Will not fix | ||
OpenShift Service Mesh 2 | openshift-service-mesh/kiali-rhel8 | Affected | ||
OpenShift Service Mesh 2.1 | openshift-service-mesh/kiali-rhel8 | Out of support scope | ||
OpenShift Service Mesh 2.1 | servicemesh-grafana | Out of support scope | ||
OpenShift Service Mesh 2.1 | servicemesh-prometheus | Out of support scope | ||
Red Hat A-MQ Online | loader-utils | Not affected | ||
Red Hat build of Apicurio Registry 2 | loader-utils | Not affected | ||
Red Hat Data Grid 8 | loader-utils | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
8.1 High
CVSS3
Связанные уязвимости
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.
Prototype pollution vulnerability in function parseQuery in parseQuery ...
EPSS
8.1 High
CVSS3