CVE-2023-28154Webpack vulnerability

10 documents7 sources
Severity
9.8CRITICALNVD
EPSS
1.3%
top 19.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 13
Latest updateMay 18

Description

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages7 packages

npmwebpack/webpack5.0.05.76.0
NVDwebpack.js/webpack5.0.05.76.0
debiandebian/node-webpack< node-webpack 5.75.0+dfsg+~cs17.16.14-1+deb12u1 (bookworm)
CVEListV5clusterlabs/pcsAffects pcs v0.11.4-6.el9, Fixed in pcs v0.11.4-7.el9_2
NVDclusterlabs/pcs0.11.4-6.el9

Patches

🔴Vulnerability Details

4
GHSA
GHSA-6rhm-fw89-rh2q: It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 92023-05-18
OSV
CVE-2023-28154: Webpack 5 before 52023-03-13
GHSA
Cross-realm object access in Webpack 52023-03-13
OSV
Cross-realm object access in Webpack 52023-03-13

📋Vendor Advisories

4
Red Hat
pcs: webpack: Regression of CVE-2023-28154 fixes in the Red Hat Enterprise Linux2023-05-09
Microsoft
Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain acce2023-03-14
Red Hat
webpack: avoid cross-realm objects2023-03-13
Debian
CVE-2023-28154: node-webpack - Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPl...2023