📂 Vulnerable Library - file-loader-6.1.1.tgz
A file loader module for webpack
Findings
| Finding |
Severity |
🎯 CVSS |
Exploit Maturity |
EPSS |
Library |
Type |
Fixed in |
Remediation Available |
Reachability |
| CVE-2022-37601 |
🟣 Critical |
9.3 |
Not Defined |
24.6% |
loader-utils-2.0.0.tgz |
Transitive |
N/A |
❌ |
Unreachable |
| CVE-2022-37601 |
🟣 Critical |
9.3 |
Not Defined |
24.6% |
loader-utils-2.0.2.tgz |
Transitive |
N/A |
❌ |
Unreachable |
| CVE-2022-37599 |
🔴 High |
8.7 |
Not Defined |
7.1000004% |
loader-utils-2.0.0.tgz |
Transitive |
N/A |
❌ |
Unreachable |
| CVE-2022-37599 |
🔴 High |
8.7 |
Not Defined |
7.1000004% |
loader-utils-2.0.2.tgz |
Transitive |
N/A |
❌ |
Unreachable |
| CVE-2022-37603 |
🔴 High |
8.7 |
Not Defined |
1.7% |
loader-utils-2.0.2.tgz |
Transitive |
N/A |
❌ |
Unreachable |
| CVE-2022-37603 |
🔴 High |
8.7 |
Not Defined |
1.7% |
loader-utils-2.0.0.tgz |
Transitive |
N/A |
❌ |
Unreachable |
Details
🟣CVE-2022-37601
Vulnerable Library - loader-utils-2.0.0.tgz
utils for webpack loaders
Library home page: https://registry.npmjs.org/loader-utils/-/loader-utils-2.0.0.tgz
Dependency Hierarchy:
-
style-loader-1.3.0.tgz (Root Library)
- ❌ loader-utils-2.0.0.tgz (Vulnerable Library)
-
react-refresh-webpack-plugin-0.5.7.tgz (Root Library)
- ❌ loader-utils-2.0.0.tgz (Vulnerable Library)
-
url-loader-4.1.1.tgz (Root Library)
- ❌ loader-utils-2.0.0.tgz (Vulnerable Library)
-
css-loader-4.3.0.tgz (Root Library)
- ❌ loader-utils-2.0.0.tgz (Vulnerable Library)
-
file-loader-6.1.1.tgz (Root Library)
- ❌ loader-utils-2.0.0.tgz (Vulnerable Library)
-
resolve-url-loader-5.0.0.tgz (Root Library)
- ❌ loader-utils-2.0.0.tgz (Vulnerable Library)
Reachability Analysis
The vulnerable code is unreachable
Vulnerability Details
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.
Publish Date: Oct 12, 2022 12:00 AM
URL: CVE-2022-37601
Threat Assessment
Exploit Maturity:Not Defined
EPSS:24.6%
Score: 9.3
Suggested Fix
Type: Upgrade version
Origin: GHSA-76p3-8jx3-jpfq
Release Date: Oct 12, 2022 12:00 AM
Fix Resolution : loader-utils - 2.0.3,loader-utils - 1.4.1
🟣CVE-2022-37601
Vulnerable Library - loader-utils-2.0.2.tgz
utils for webpack loaders
Library home page: https://registry.npmjs.org/loader-utils/-/loader-utils-2.0.2.tgz
Dependency Hierarchy:
-
style-loader-1.3.0.tgz (Root Library)
- ❌ loader-utils-2.0.2.tgz (Vulnerable Library)
-
react-refresh-webpack-plugin-0.5.7.tgz (Root Library)
- ❌ loader-utils-2.0.2.tgz (Vulnerable Library)
-
url-loader-4.1.1.tgz (Root Library)
- ❌ loader-utils-2.0.2.tgz (Vulnerable Library)
-
css-loader-4.3.0.tgz (Root Library)
- ❌ loader-utils-2.0.2.tgz (Vulnerable Library)
-
file-loader-6.1.1.tgz (Root Library)
- ❌ loader-utils-2.0.2.tgz (Vulnerable Library)
-
resolve-url-loader-3.1.4.tgz (Root Library)
- adjust-sourcemap-loader-3.0.0.tgz
- ❌ loader-utils-2.0.2.tgz (Vulnerable Library)
Reachability Analysis
The vulnerable code is unreachable
Vulnerability Details
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.
Publish Date: Oct 12, 2022 12:00 AM
URL: CVE-2022-37601
Threat Assessment
Exploit Maturity:Not Defined
EPSS:24.6%
Score: 9.3
Suggested Fix
Type: Upgrade version
Origin: GHSA-76p3-8jx3-jpfq
Release Date: Oct 12, 2022 12:00 AM
Fix Resolution : loader-utils - 2.0.3,loader-utils - 1.4.1
🔴CVE-2022-37599
Vulnerable Library - loader-utils-2.0.0.tgz
utils for webpack loaders
Library home page: https://registry.npmjs.org/loader-utils/-/loader-utils-2.0.0.tgz
Dependency Hierarchy:
-
style-loader-1.3.0.tgz (Root Library)
- ❌ loader-utils-2.0.0.tgz (Vulnerable Library)
-
react-refresh-webpack-plugin-0.5.7.tgz (Root Library)
- ❌ loader-utils-2.0.0.tgz (Vulnerable Library)
-
url-loader-4.1.1.tgz (Root Library)
- ❌ loader-utils-2.0.0.tgz (Vulnerable Library)
-
css-loader-4.3.0.tgz (Root Library)
- ❌ loader-utils-2.0.0.tgz (Vulnerable Library)
-
file-loader-6.1.1.tgz (Root Library)
- ❌ loader-utils-2.0.0.tgz (Vulnerable Library)
-
resolve-url-loader-5.0.0.tgz (Root Library)
- ❌ loader-utils-2.0.0.tgz (Vulnerable Library)
Reachability Analysis
The vulnerable code is unreachable
Vulnerability Details
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js.
Publish Date: Oct 11, 2022 12:00 AM
URL: CVE-2022-37599
Threat Assessment
Exploit Maturity:Not Defined
EPSS:7.1000004%
Score: 8.7
Suggested Fix
Type: Upgrade version
Origin: https://osv.dev/vulnerability/CVE-2022-37599
Release Date: Oct 11, 2022 12:00 AM
Fix Resolution : https://github.com/webpack/loader-utils.git - no_fix,loader-utils - 1.4.2,loader-utils - 2.0.4,loader-utils - 3.2.1
🔴CVE-2022-37599
Vulnerable Library - loader-utils-2.0.2.tgz
utils for webpack loaders
Library home page: https://registry.npmjs.org/loader-utils/-/loader-utils-2.0.2.tgz
Dependency Hierarchy:
-
style-loader-1.3.0.tgz (Root Library)
- ❌ loader-utils-2.0.2.tgz (Vulnerable Library)
-
react-refresh-webpack-plugin-0.5.7.tgz (Root Library)
- ❌ loader-utils-2.0.2.tgz (Vulnerable Library)
-
url-loader-4.1.1.tgz (Root Library)
- ❌ loader-utils-2.0.2.tgz (Vulnerable Library)
-
css-loader-4.3.0.tgz (Root Library)
- ❌ loader-utils-2.0.2.tgz (Vulnerable Library)
-
file-loader-6.1.1.tgz (Root Library)
- ❌ loader-utils-2.0.2.tgz (Vulnerable Library)
-
resolve-url-loader-3.1.4.tgz (Root Library)
- adjust-sourcemap-loader-3.0.0.tgz
- ❌ loader-utils-2.0.2.tgz (Vulnerable Library)
Reachability Analysis
The vulnerable code is unreachable
Vulnerability Details
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js.
Publish Date: Oct 11, 2022 12:00 AM
URL: CVE-2022-37599
Threat Assessment
Exploit Maturity:Not Defined
EPSS:7.1000004%
Score: 8.7
Suggested Fix
Type: Upgrade version
Origin: https://osv.dev/vulnerability/CVE-2022-37599
Release Date: Oct 11, 2022 12:00 AM
Fix Resolution : https://github.com/webpack/loader-utils.git - no_fix,loader-utils - 1.4.2,loader-utils - 2.0.4,loader-utils - 3.2.1
🔴CVE-2022-37603
Vulnerable Library - loader-utils-2.0.2.tgz
utils for webpack loaders
Library home page: https://registry.npmjs.org/loader-utils/-/loader-utils-2.0.2.tgz
Dependency Hierarchy:
-
style-loader-1.3.0.tgz (Root Library)
- ❌ loader-utils-2.0.2.tgz (Vulnerable Library)
-
react-refresh-webpack-plugin-0.5.7.tgz (Root Library)
- ❌ loader-utils-2.0.2.tgz (Vulnerable Library)
-
url-loader-4.1.1.tgz (Root Library)
- ❌ loader-utils-2.0.2.tgz (Vulnerable Library)
-
css-loader-4.3.0.tgz (Root Library)
- ❌ loader-utils-2.0.2.tgz (Vulnerable Library)
-
file-loader-6.1.1.tgz (Root Library)
- ❌ loader-utils-2.0.2.tgz (Vulnerable Library)
-
resolve-url-loader-3.1.4.tgz (Root Library)
- adjust-sourcemap-loader-3.0.0.tgz
- ❌ loader-utils-2.0.2.tgz (Vulnerable Library)
Reachability Analysis
The vulnerable code is unreachable
Vulnerability Details
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the url variable in interpolateName.js.
Publish Date: Oct 14, 2022 12:00 AM
URL: CVE-2022-37603
Threat Assessment
Exploit Maturity:Not Defined
EPSS:1.7%
Score: 8.7
Suggested Fix
Type: Upgrade version
Origin: GHSA-3rfm-jhwj-7488
Release Date: Oct 14, 2022 12:00 AM
Fix Resolution : loader-utils - 1.4.2,loader-utils - 3.2.1,loader-utils - 2.0.4
🔴CVE-2022-37603
Vulnerable Library - loader-utils-2.0.0.tgz
utils for webpack loaders
Library home page: https://registry.npmjs.org/loader-utils/-/loader-utils-2.0.0.tgz
Dependency Hierarchy:
-
style-loader-1.3.0.tgz (Root Library)
- ❌ loader-utils-2.0.0.tgz (Vulnerable Library)
-
react-refresh-webpack-plugin-0.5.7.tgz (Root Library)
- ❌ loader-utils-2.0.0.tgz (Vulnerable Library)
-
url-loader-4.1.1.tgz (Root Library)
- ❌ loader-utils-2.0.0.tgz (Vulnerable Library)
-
css-loader-4.3.0.tgz (Root Library)
- ❌ loader-utils-2.0.0.tgz (Vulnerable Library)
-
file-loader-6.1.1.tgz (Root Library)
- ❌ loader-utils-2.0.0.tgz (Vulnerable Library)
-
resolve-url-loader-5.0.0.tgz (Root Library)
- ❌ loader-utils-2.0.0.tgz (Vulnerable Library)
Reachability Analysis
The vulnerable code is unreachable
Vulnerability Details
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the url variable in interpolateName.js.
Publish Date: Oct 14, 2022 12:00 AM
URL: CVE-2022-37603
Threat Assessment
Exploit Maturity:Not Defined
EPSS:1.7%
Score: 8.7
Suggested Fix
Type: Upgrade version
Origin: GHSA-3rfm-jhwj-7488
Release Date: Oct 14, 2022 12:00 AM
Fix Resolution : loader-utils - 1.4.2,loader-utils - 3.2.1,loader-utils - 2.0.4
📂 Vulnerable Library - file-loader-6.1.1.tgz
A file loader module for webpack
Findings
Details
🟣CVE-2022-37601
Vulnerable Library - loader-utils-2.0.0.tgz
utils for webpack loaders
Library home page: https://registry.npmjs.org/loader-utils/-/loader-utils-2.0.0.tgz
Dependency Hierarchy:
style-loader-1.3.0.tgz (Root Library)
react-refresh-webpack-plugin-0.5.7.tgz (Root Library)
url-loader-4.1.1.tgz (Root Library)
css-loader-4.3.0.tgz (Root Library)
file-loader-6.1.1.tgz (Root Library)
resolve-url-loader-5.0.0.tgz (Root Library)
Reachability Analysis
The vulnerable code is unreachable
Vulnerability Details
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.
Publish Date: Oct 12, 2022 12:00 AM
URL: CVE-2022-37601
Threat Assessment
Exploit Maturity:Not Defined
EPSS:24.6%
Score: 9.3
Suggested Fix
Type: Upgrade version
Origin: GHSA-76p3-8jx3-jpfq
Release Date: Oct 12, 2022 12:00 AM
Fix Resolution : loader-utils - 2.0.3,loader-utils - 1.4.1
🟣CVE-2022-37601
Vulnerable Library - loader-utils-2.0.2.tgz
utils for webpack loaders
Library home page: https://registry.npmjs.org/loader-utils/-/loader-utils-2.0.2.tgz
Dependency Hierarchy:
style-loader-1.3.0.tgz (Root Library)
react-refresh-webpack-plugin-0.5.7.tgz (Root Library)
url-loader-4.1.1.tgz (Root Library)
css-loader-4.3.0.tgz (Root Library)
file-loader-6.1.1.tgz (Root Library)
resolve-url-loader-3.1.4.tgz (Root Library)
Reachability Analysis
The vulnerable code is unreachable
Vulnerability Details
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.
Publish Date: Oct 12, 2022 12:00 AM
URL: CVE-2022-37601
Threat Assessment
Exploit Maturity:Not Defined
EPSS:24.6%
Score: 9.3
Suggested Fix
Type: Upgrade version
Origin: GHSA-76p3-8jx3-jpfq
Release Date: Oct 12, 2022 12:00 AM
Fix Resolution : loader-utils - 2.0.3,loader-utils - 1.4.1
🔴CVE-2022-37599
Vulnerable Library - loader-utils-2.0.0.tgz
utils for webpack loaders
Library home page: https://registry.npmjs.org/loader-utils/-/loader-utils-2.0.0.tgz
Dependency Hierarchy:
style-loader-1.3.0.tgz (Root Library)
react-refresh-webpack-plugin-0.5.7.tgz (Root Library)
url-loader-4.1.1.tgz (Root Library)
css-loader-4.3.0.tgz (Root Library)
file-loader-6.1.1.tgz (Root Library)
resolve-url-loader-5.0.0.tgz (Root Library)
Reachability Analysis
The vulnerable code is unreachable
Vulnerability Details
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js.
Publish Date: Oct 11, 2022 12:00 AM
URL: CVE-2022-37599
Threat Assessment
Exploit Maturity:Not Defined
EPSS:7.1000004%
Score: 8.7
Suggested Fix
Type: Upgrade version
Origin: https://osv.dev/vulnerability/CVE-2022-37599
Release Date: Oct 11, 2022 12:00 AM
Fix Resolution : https://github.com/webpack/loader-utils.git - no_fix,loader-utils - 1.4.2,loader-utils - 2.0.4,loader-utils - 3.2.1
🔴CVE-2022-37599
Vulnerable Library - loader-utils-2.0.2.tgz
utils for webpack loaders
Library home page: https://registry.npmjs.org/loader-utils/-/loader-utils-2.0.2.tgz
Dependency Hierarchy:
style-loader-1.3.0.tgz (Root Library)
react-refresh-webpack-plugin-0.5.7.tgz (Root Library)
url-loader-4.1.1.tgz (Root Library)
css-loader-4.3.0.tgz (Root Library)
file-loader-6.1.1.tgz (Root Library)
resolve-url-loader-3.1.4.tgz (Root Library)
Reachability Analysis
The vulnerable code is unreachable
Vulnerability Details
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js.
Publish Date: Oct 11, 2022 12:00 AM
URL: CVE-2022-37599
Threat Assessment
Exploit Maturity:Not Defined
EPSS:7.1000004%
Score: 8.7
Suggested Fix
Type: Upgrade version
Origin: https://osv.dev/vulnerability/CVE-2022-37599
Release Date: Oct 11, 2022 12:00 AM
Fix Resolution : https://github.com/webpack/loader-utils.git - no_fix,loader-utils - 1.4.2,loader-utils - 2.0.4,loader-utils - 3.2.1
🔴CVE-2022-37603
Vulnerable Library - loader-utils-2.0.2.tgz
utils for webpack loaders
Library home page: https://registry.npmjs.org/loader-utils/-/loader-utils-2.0.2.tgz
Dependency Hierarchy:
style-loader-1.3.0.tgz (Root Library)
react-refresh-webpack-plugin-0.5.7.tgz (Root Library)
url-loader-4.1.1.tgz (Root Library)
css-loader-4.3.0.tgz (Root Library)
file-loader-6.1.1.tgz (Root Library)
resolve-url-loader-3.1.4.tgz (Root Library)
Reachability Analysis
The vulnerable code is unreachable
Vulnerability Details
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the url variable in interpolateName.js.
Publish Date: Oct 14, 2022 12:00 AM
URL: CVE-2022-37603
Threat Assessment
Exploit Maturity:Not Defined
EPSS:1.7%
Score: 8.7
Suggested Fix
Type: Upgrade version
Origin: GHSA-3rfm-jhwj-7488
Release Date: Oct 14, 2022 12:00 AM
Fix Resolution : loader-utils - 1.4.2,loader-utils - 3.2.1,loader-utils - 2.0.4
🔴CVE-2022-37603
Vulnerable Library - loader-utils-2.0.0.tgz
utils for webpack loaders
Library home page: https://registry.npmjs.org/loader-utils/-/loader-utils-2.0.0.tgz
Dependency Hierarchy:
style-loader-1.3.0.tgz (Root Library)
react-refresh-webpack-plugin-0.5.7.tgz (Root Library)
url-loader-4.1.1.tgz (Root Library)
css-loader-4.3.0.tgz (Root Library)
file-loader-6.1.1.tgz (Root Library)
resolve-url-loader-5.0.0.tgz (Root Library)
Reachability Analysis
The vulnerable code is unreachable
Vulnerability Details
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the url variable in interpolateName.js.
Publish Date: Oct 14, 2022 12:00 AM
URL: CVE-2022-37603
Threat Assessment
Exploit Maturity:Not Defined
EPSS:1.7%
Score: 8.7
Suggested Fix
Type: Upgrade version
Origin: GHSA-3rfm-jhwj-7488
Release Date: Oct 14, 2022 12:00 AM
Fix Resolution : loader-utils - 1.4.2,loader-utils - 3.2.1,loader-utils - 2.0.4