Webpack.Js Loader-Utils vulnerabilities
3 known vulnerabilities affecting webpack.js/loader-utils.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2
Vulnerabilities
Page 1 of 1
CVE-2022-37603HIGHCVSS 7.5fixed in 1.4.2≥ 2.0.0, < 2.0.4+1 more2022-10-14
CVE-2022-37603 [HIGH] CWE-1333 CVE-2022-37603: A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpo
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the url variable in interpolateName.js.
ghsanvdosv
CVE-2022-37601CRITICALCVSS 9.8fixed in 1.4.1≥ 2.0.0, < 2.0.32022-10-12
CVE-2022-37601 [CRITICAL] CWE-1321 CVE-2022-37601: Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils vi
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.
ghsanvdosv
CVE-2022-37599HIGHCVSS 7.5≥ 1.0.0, < 1.4.2≥ 2.0.0, < 2.0.4+1 more2022-10-11
CVE-2022-37599 [HIGH] CWE-1333 CVE-2022-37599: A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpo
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js.
ghsanvdosv