CVE Vulnerabilities

CVE-2023-28154

Published: Mar 13, 2023 | Modified: Nov 07, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
9.1 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Ubuntu
MEDIUM

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.

Affected Software

Name Vendor Start Version End Version
Webpack Webpack.js 5.0.0 (including) 5.76.0 (excluding)
Red Hat Enterprise Linux 9 RedHat pcs-0:0.11.3-4.el9_1.3 *
Node-webpack Ubuntu bionic *
Node-webpack Ubuntu kinetic *
Node-webpack Ubuntu lunar *
Node-webpack Ubuntu mantic *
Node-webpack Ubuntu trusty *
Node-webpack Ubuntu xenial *

References