Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-28154

Опубликовано: 13 мар. 2023
Источник: redhat
CVSS3: 9.1

Описание

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.

A flaw was found in the webpack package, which could allow a remote attacker to bypass security restrictions caused by the mishandling of the magic comment feature by the ImportParserPlugin.js. This flaw allows an attacker to gain access to the real global object by sending a specially-crafted request.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and ServicesodoAffected
OpenShift Pipelinesopenshift-pipelines/pipelines-hub-ui-rhel8Affected
OpenShift Service Mesh 2.1servicemesh-grafanaNot affected
OpenShift Service Mesh 2.1servicemesh-prometheusNot affected
Red Hat A-MQ OnlinewebpackAffected
Red Hat Ansible Automation Platform 2aap-azure-uiNot affected
Red Hat build of Apicurio Registry 2webpackNot affected
Red Hat Data Grid 8webpackNot affected
Red Hat Decision Manager 7webpackNot affected
Red Hat Enterprise Linux 6firefoxNot affected

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=2179227webpack: avoid cross-realm objects

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 2 лет назад

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.

CVSS3: 9.8
nvd
больше 2 лет назад

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.

CVSS3: 9.8
debian
больше 2 лет назад

Webpack 5 before 5.76.0 does not avoid cross-realm object access. Impo ...

CVSS3: 9.8
github
больше 2 лет назад

Cross-realm object access in Webpack 5

oracle-oval
больше 2 лет назад

ELSA-2023-12235: pcs security update (IMPORTANT)

9.1 Critical

CVSS3