You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Description
Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.
Description
Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.
Affected versions
Patched versions
5.76.0
References
https://nvd.nist.gov/vuln/detail/CVE-2023-28154
webpack/webpack#16500
webpack/webpack@v5.75.0...v5.76.0
Published by the National Vulnerability Database last week
Published to the GitHub Advisory Database last week
The text was updated successfully, but these errors were encountered: