Open
Description
A critical severity vulnerability has been discovered in your project.
Project Name: kondukto-ui-vue
Scanner Name: dependabot
File: package-lock.json
Packages:
- loader-utils:1.4.0
References:
- https://nvd.nist.gov/vuln/detail/CVE-2022-37601
- [CVE-2022-37601]/Prototype pollution found in parseQuery.js webpack/loader-utils#212
- https://github.com/webpack/loader-utils/blob/d9f4e23cf411d8556f8bac2d3bf05a6e0103b568/lib/parseQuery.js#L11
- https://github.com/webpack/loader-utils/blob/d9f4e23cf411d8556f8bac2d3bf05a6e0103b568/lib/parseQuery.js#L47
- https://github.com/webpack/loader-utils/releases/tag/v2.0.3
- fix: Resolve potential prototype polution exploit webpack/loader-utils#217
- fix: security problem webpack/loader-utils#220
- https://github.com/webpack/loader-utils/releases/tag/v1.4.1
- GHSA-76p3-8jx3-jpfq
Tool Description: Summary: Prototype pollution in webpack loader-utils.
Description: Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils prior to version 2.0.3 via the name variable in parseQuery.js.