Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-28154

Опубликовано: 13 мар. 2023
Источник: redhat
CVSS3: 9.1

Описание

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.

A flaw was found in the webpack package, which could allow a remote attacker to bypass security restrictions caused by the mishandling of the magic comment feature by the ImportParserPlugin.js. This flaw allows an attacker to gain access to the real global object by sending a specially-crafted request.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and ServicesodoAffected
OpenShift Pipelinesopenshift-pipelines/pipelines-hub-ui-rhel8Affected
OpenShift Service Mesh 2.1servicemesh-grafanaNot affected
OpenShift Service Mesh 2.1servicemesh-prometheusNot affected
Red Hat A-MQ OnlinewebpackAffected
Red Hat Ansible Automation Platform 2aap-azure-uiNot affected
Red Hat build of Apicurio Registry 2webpackNot affected
Red Hat Data Grid 8webpackNot affected
Red Hat Decision Manager 7webpackNot affected
Red Hat Enterprise Linux 6firefoxNot affected

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=2179227webpack: avoid cross-realm objects

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 3 года назад

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.

CVSS3: 9.8
nvd
почти 3 года назад

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.

msrc
5 месяцев назад

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.

CVSS3: 9.8
debian
почти 3 года назад

Webpack 5 before 5.76.0 does not avoid cross-realm object access. Impo ...

CVSS3: 9.8
github
почти 3 года назад

Cross-realm object access in Webpack 5

9.1 Critical

CVSS3