Описание
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the url variable in interpolateName.js.
A flaw was found in loader-utils webpack library. When the url variable from interpolateName is set, the prototype can be polluted. This issue could lead to a regular expression Denial of Service (ReDoS), affecting the availability of the affected component.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Migration Toolkit for Virtualization | migration-toolkit-virtualization/mtv-ui-rhel8 | Fix deferred | ||
OpenShift Developer Tools and Services | odo | Will not fix | ||
OpenShift Service Mesh 2 | openshift-service-mesh/kiali-rhel8 | Will not fix | ||
OpenShift Service Mesh 2.0 | openshift-service-mesh/kiali-rhel8 | Not affected | ||
OpenShift Service Mesh 2.0 | servicemesh-grafana | Not affected | ||
OpenShift Service Mesh 2.0 | servicemesh-prometheus | Not affected | ||
OpenShift Service Mesh 2.1 | openshift-service-mesh/kiali-rhel8 | Affected | ||
OpenShift Service Mesh 2.1 | servicemesh-grafana | Not affected | ||
OpenShift Service Mesh 2.1 | servicemesh-prometheus | Not affected | ||
Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/application-ui-rhel8 | Not affected |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the url variable in interpolateName.js.
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the url variable in interpolateName.js.
A Regular expression denial of service (ReDoS) flaw was found in Funct ...
loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS) via url variable
7.5 High
CVSS3