Debian Node-Loader-Utils vulnerabilities
3 known vulnerabilities affecting debian/node-loader-utils.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2
Vulnerabilities
Page 1 of 1
CVE-2022-37601CRITICALCVSS 9.8fixed in node-loader-utils 2.0.3-1 (bookworm)2022
CVE-2022-37601 [CRITICAL] CVE-2022-37601: node-loader-utils - Prototype pollution vulnerability in function parseQuery in parseQuery.js in web...
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.
Scope: local
bookworm: resolved (fixed in 2.0.3-1)
bullseye: resolved (fixed in 2.0.0-1+deb11u1)
forky: resolved (fixed in 2.0.3-1)
sid: resolved (fixed in 2.0.3-1)
debian
CVE-2022-37599HIGHCVSS 7.5fixed in node-loader-utils 2.0.4-1 (bookworm)2022
CVE-2022-37599 [HIGH] CVE-2022-37599: node-loader-utils - A Regular expression denial of service (ReDoS) flaw was found in Function interp...
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js.
Scope: local
bookworm: resolved (fixed in 2.0.4-1)
bullseye: resolved (fixed in 2.0.0-1+deb11u1)
forky: resolved (fixed in 2.0.4-1)
sid: resolved (fixed in 2.0.4-1
debian
CVE-2022-37603HIGHCVSS 7.5fixed in node-loader-utils 2.0.4-1 (bookworm)2022
CVE-2022-37603 [HIGH] CVE-2022-37603: node-loader-utils - A Regular expression denial of service (ReDoS) flaw was found in Function interp...
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the url variable in interpolateName.js.
Scope: local
bookworm: resolved (fixed in 2.0.4-1)
bullseye: resolved (fixed in 2.0.0-1+deb11u1)
forky: resolved (fixed in 2.0.4-1)
sid: resolved (fixed in 2.0.4-1)
trixie:
debian