Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.
References
Link | Resource |
---|---|
https://github.com/webpack/webpack/compare/v5.75.0...v5.76.0 | Patch Product |
https://github.com/webpack/webpack/pull/16500 | Patch |
Configurations
Information
Published : 2023-03-12 18:15
Updated : 2023-03-17 08:19
NVD link : CVE-2023-28154
Mitre link : CVE-2023-28154
JSON object : View
CWE
Products Affected
webpack.js
- webpack