PT-2022-24021 · Webpack+2 · Loader-Utils+2

Kundarsowjanya

·

Published

2022-10-11

·

Updated

2025-12-11

·

CVE-2022-37599

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions webpack loader-utils version 2.0.0
Description A Regular expression denial of service (ReDoS) flaw was found in the interpolateName function in interpolateName.js via the resourcePath variable. This issue could be exploited by sending crafted requests with badly or maliciously formed strings, causing a system to crash or take a disproportional amount of time to process.
Recommendations For version 2.0.0, update to version 2.0.4 to resolve the issue. As a temporary workaround, consider restricting the use of the interpolateName function until a patch is available. Avoid using the resourcePath variable in the affected interpolateName.js file until the issue is resolved.

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2022-37599
GHSA-HHQ3-FF78-JV3G
MGASA-2025-0194

Affected Products

Confluence
Red Os
Loader-Utils