Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Supraja Baskar

#25576of 53,633
9.8Total CVSS
Vulnerabilities · 1
PT-2022-24022
9.8
2022-10-12
Webpack · Loader-Utils · CVE-2022-37601
**Name of the Vulnerable Software and Affected Versions** loader-utils versions prior to 1.4.1 loader-utils versions prior to 2.0.3 **Description** The issue is related to a prototype pollution vulnerability in the `parseQuery` function within `parseQuery.js` in webpack loader-utils. This vulnerability is exploited via the `name` variable in `parseQuery.js`. **Recommendations** For versions prior to 1.4.1, update to version 1.4.1 or later. For versions prior to 2.0.3, update to version 2.0.3 or later.