Closed github-actions[bot] closed 1 year ago
Although the Veracode issue indicates that the vulnerability is fixed in v3.x, in fact the fix was backported to v1 and v2 as well.
https://github.com/webpack/loader-utils/issues/213#issuecomment-1314604293
v1 patch: https://github.com/webpack/loader-utils/pull/226 v2 patch: https://github.com/webpack/loader-utils/pull/225
Therefore this issue is a NOOP.
Veracode Software Composition Analysis
url
variable of theinterpolateName
function ininterpolateName.js
. A remote attacker can cause denial of service via malicious regex.Links: