We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.
Reserved 2022-08-08 | Published 2022-10-12 | Updated 2024-10-28 | Assigner mitregithub.com/...d8556f8bac2d3bf05a6e0103b568/lib/parseQuery.js
github.com/...d8556f8bac2d3bf05a6e0103b568/lib/parseQuery.js
github.com/webpack/loader-utils/issues/212
github.com/webpack/loader-utils/issues/212
dl.acm.org/doi/abs/10.1145/3488932.3497769
dl.acm.org/doi/pdf/10.1145/3488932.3497769
users.encs.concordia.ca/.../JS-vulnerability-aisaccs2022.pdf
github.com/xmldom/xmldom/issues/436
lists.debian.org/debian-lts-announce/2022/12/msg00044.html ([debian-lts-announce] 20221231 [SECURITY] [DLA 3258-1] node-loader-utils security update)
Support options