9.8
CVSSv3

CVE-2023-28154

Published: 13/03/2023 Updated: 07/11/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Webpack 5 prior to 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

webpack.js webpack

Vendor Advisories

Synopsis Important: pcs security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for pcs is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as having a security ...
Debian Bug report logs - #1032904 node-webpack: CVE-2023-28154 Package: src:node-webpack; Maintainer for src:node-webpack is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 13 Mar 2023 19:27:02 UTC Severity: important Tags: ...

Github Repositories

Demo of JFrog Frogbot capabilities

JFrog Frogbot Branch Status master dev Table of contents πŸ€– About JFrog Frogbot πŸ–₯️ Installing Frogbot πŸš₯ Using Frogbot Scanning pull requests Scanning repositories and fixing issues πŸ“› Adding the Frogbot badge πŸ”₯ Reporting issues πŸ’» Contributions πŸ€– About JFrog Frogbot Overview JFrog Frogbot is a Git bot that scans your git repositor