Логотип exploitDog
bind:CVE-2023-28154
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-28154

Количество 6

Количество 6

ubuntu логотип

CVE-2023-28154

больше 2 лет назад

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2023-28154

больше 2 лет назад

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2023-28154

больше 2 лет назад

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2023-28154

больше 2 лет назад

Webpack 5 before 5.76.0 does not avoid cross-realm object access. Impo ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-hc6q-2mpp-qw7j

больше 2 лет назад

Cross-realm object access in Webpack 5

CVSS3: 9.8
EPSS: Низкий
oracle-oval логотип

ELSA-2023-12235

больше 2 лет назад

ELSA-2023-12235: pcs security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-28154

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2023-28154

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.

CVSS3: 9.1
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-28154

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-28154

Webpack 5 before 5.76.0 does not avoid cross-realm object access. Impo ...

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-hc6q-2mpp-qw7j

Cross-realm object access in Webpack 5

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
oracle-oval логотип
ELSA-2023-12235

ELSA-2023-12235: pcs security update (IMPORTANT)

больше 2 лет назад

Уязвимостей на страницу