CVE-2022-37599
published 2022-10-11CVE-2022-37599: A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the…
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.13%
80.2th percentile
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-loader-utils | < node-loader-utils 2.0.4-1 (bookworm) | node-loader-utils 2.0.4-1 (bookworm) |
| webpack.js | loader-utils | >= 1.0.0 < 1.4.2 | 1.4.2 |
| webpack.js | loader-utils | >= 1.0.0 < 1.4.2 | 1.4.2 |
| webpack.js | loader-utils | >= 2.0.0 < 2.0.4 | 2.0.4 |
| webpack.js | loader-utils | >= 2.0.0 < 2.0.4 | 2.0.4 |
| webpack.js | loader-utils | >= 3.0.0 < 3.2.1 | 3.2.1 |
| webpack.js | loader-utils | >= 3.0.0 < 3.2.1 | 3.2.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
loader-utils: regular expression denial of service in interpolateName.js
vendor_redhat·2022-10-14·CVSS 7.5
CVE-2022-37599 [HIGH] CWE-400 loader-utils: regular expression denial of service in interpolateName.js
loader-utils: regular expression denial of service in interpolateName.js
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js.
A flaw was found in the interpolateName function in interpolateName.js in the webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js. This flaw can lead to a regular expression denial of service (ReDoS).
Statement: In Red Hat OpenShift Logging the openshift-logging/kibana6-rhel8 container and openshift-logging/logging-view-plugin-rhel8 bundles many nodejs packages as a build time dependencies, including loader-utils package. The vulnerable code is not used hence the impact to OpenShift Logging by thi
Debian
CVE-2022-37599: node-loader-utils - A Regular expression denial of service (ReDoS) flaw was found in Function interp...
vendor_debian·2022·CVSS 7.5
CVE-2022-37599 [HIGH] CVE-2022-37599: node-loader-utils - A Regular expression denial of service (ReDoS) flaw was found in Function interp...
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js.
Scope: local
bookworm: resolved (fixed in 2.0.4-1)
bullseye: resolved (fixed in 2.0.0-1+deb11u1)
forky: resolved (fixed in 2.0.4-1)
sid: resolved (fixed in 2.0.4-1)
trixie: resolved (fixed in 2.0.4-1)
OSV
loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS)
osv·2022-10-12
CVE-2022-37599 [HIGH] loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS)
loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS)
A regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils via the resourcePath variable in interpolateName.js. A badly or maliciously formed string could be used to send crafted requests that cause a system to crash or take a disproportional amount of time to process. This issue has been patched in versions 1.4.2, 2.0.4 and 3.2.1.
GHSA
loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS)
ghsa·2022-10-12
CVE-2022-37599 [HIGH] CWE-1333 loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS)
loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS)
A regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils via the resourcePath variable in interpolateName.js. A badly or maliciously formed string could be used to send crafted requests that cause a system to crash or take a disproportional amount of time to process. This issue has been patched in versions 1.4.2, 2.0.4 and 3.2.1.
OSV
CVE-2022-37599: A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName
osv·2022-10-11·CVSS 7.5
CVE-2022-37599 [HIGH] CVE-2022-37599: A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js.
No detection rules found.
No public exploits indexed.
https://github.com/webpack/loader-utils/blob/d9f4e23cf411d8556f8bac2d3bf05a6e0103b568/lib/interpolateName.js#L38https://github.com/webpack/loader-utils/blob/d9f4e23cf411d8556f8bac2d3bf05a6e0103b568/lib/interpolateName.js#L83https://github.com/webpack/loader-utils/issues/211https://github.com/webpack/loader-utils/issues/216https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3HUE6ZR5SL73KHL7XUPAOEL6SB7HUDT2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6PVVPNSAGSDS63HQ74PJ7MZ3MU5IYNVZ/https://github.com/webpack/loader-utils/blob/d9f4e23cf411d8556f8bac2d3bf05a6e0103b568/lib/interpolateName.js#L38https://github.com/webpack/loader-utils/blob/d9f4e23cf411d8556f8bac2d3bf05a6e0103b568/lib/interpolateName.js#L83https://github.com/webpack/loader-utils/issues/211https://github.com/webpack/loader-utils/issues/216https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3HUE6ZR5SL73KHL7XUPAOEL6SB7HUDT2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6PVVPNSAGSDS63HQ74PJ7MZ3MU5IYNVZ/https://lists.fedoraproject.org/archives/list/[email protected]/message/6PVVPNSAGSDS63HQ74PJ7MZ3MU5IYNVZ/
2022-10-11
Published