-
Notifications
You must be signed in to change notification settings - Fork 8
Closed
Labels
Severity: MediumMedium severityMedium severityVeracode Dependency ScanningA Veracode identified vulnerabilityA Veracode identified vulnerability
Description
Veracode Software Composition Analysis
| Attribute | Details |
|---|---|
| Library | loader-utils |
| Description | utils for webpack loaders |
| Language | JS |
| Vulnerability | Regular Expression Denial Of Service (ReDoS) |
| Vulnerability description | loader-utils is vulnerable to regular expression denial of service. The vulnerability is due to insecure regular expression in the url variable of the interpolateName function in interpolateName.js. A remote attacker can cause denial of service via malicious regex. |
| CVE | 2022-37603 |
| CVSS score | 5 |
| Vulnerability present in version/s | 1.0.0-2.0.4 |
| Found library version/s | 1.4.2,2.0.4 |
| Vulnerability fixed in version | 3.0.0 |
| Library latest version | 3.2.1 |
| Fix |
Links:
Metadata
Metadata
Assignees
Labels
Severity: MediumMedium severityMedium severityVeracode Dependency ScanningA Veracode identified vulnerabilityA Veracode identified vulnerability