Skip to content

CVE-2022-37601 | loader-utils:1.4.0 (CWE-0) #82

Open
@ckalpakoglu

Description

@ckalpakoglu

A critical severity vulnerability has been discovered in your project.

Project Name: kondukto-ui-vue

Scanner Name: dependabot

File: package-lock.json

Packages:

  • loader-utils:1.4.0

References:

Tool Description: Summary: Prototype pollution in webpack loader-utils.
Description: Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils prior to version 2.0.3 via the name variable in parseQuery.js.

Metadata

Metadata

Assignees

Labels

KONDUKTObugSomething isn't working

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions