PT-2020-14322 · Webpack · Webpack-Subresource-Integrity
Jahed
·
Published
2020-10-19
·
Updated
2021-11-18
·
CVE-2020-15262
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
webpack-subresource-integrity versions prior to 1.5.1
Description
The issue affects dynamically loaded chunks, which receive an invalid integrity hash that is ignored by the browser. This removes the additional level of protection offered by Subresource Integrity (SRI) for such chunks. Top-level chunks are unaffected.
Recommendations
For versions prior to 1.5.1, update to version 1.5.1 to resolve the issue. As a temporary workaround, consider restricting the use of dynamically loaded chunks until the update is applied.
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webpack-Subresource-Integrity