PT-2023-21600 · Webpack+3 · Webpack+3

Jack-Works

·

Published

2023-03-13

·

Updated

2024-07-05

·

CVE-2023-28154

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Webpack versions prior to 5.76.0
Description The issue concerns cross-realm object access. Specifically, the ImportParserPlugin.js mishandles the magic comment feature, allowing an attacker who controls a property of an untrusted object to obtain access to the real global object.
Recommendations For Webpack versions prior to 5.76.0, update to version 5.76.0 or later to resolve the issue.

Fix

Related Identifiers

ALSA-2023:1591
ALSA-2023:2652
CVE-2023-28154
GHSA-HC6Q-2MPP-QW7J
OPENSUSE-SU-2024:12803-1
OPENSUSE-SU-2024:12979-1
OPENSUSE-SU-2024:14106-1
RHSA-2023:1591
RHSA-2023_1591
RLSA-2023:1591

Affected Products

Almalinux
Red Hat
Rocky Linux
Webpack