📂 Vulnerable Library - postcss-loader-3.0.0.tgz
PostCSS loader for webpack
Findings
| Finding |
Severity |
🎯 CVSS |
Exploit Maturity |
EPSS |
Library |
Type |
Fixed in |
Remediation Available |
Reachability |
| CVE-2022-37601 |
🟣 Critical |
9.3 |
Not Defined |
24.6% |
loader-utils-1.4.0.tgz |
Transitive |
N/A |
❌ |
Reachable |
| CVE-2022-37599 |
🔴 High |
8.7 |
Not Defined |
7.1000004% |
loader-utils-1.4.0.tgz |
Transitive |
N/A |
❌ |
Reachable |
| CVE-2022-37603 |
🔴 High |
8.7 |
Not Defined |
1.7% |
loader-utils-1.4.0.tgz |
Transitive |
N/A |
❌ |
Reachable |
Details
🟣CVE-2022-37601
Vulnerable Library - loader-utils-1.4.0.tgz
utils for webpack loaders
Library home page: https://registry.npmjs.org/loader-utils/-/loader-utils-1.4.0.tgz
Dependency Hierarchy:
-
babel-loader-8.1.0.tgz (Root Library)
- ❌ loader-utils-1.4.0.tgz (Vulnerable Library)
-
postcss-loader-3.0.0.tgz (Root Library)
- ❌ loader-utils-1.4.0.tgz (Vulnerable Library)
-
mini-css-extract-plugin-0.11.3.tgz (Root Library)
- ❌ loader-utils-1.4.0.tgz (Vulnerable Library)
-
html-webpack-plugin-4.5.0.tgz (Root Library)
- ❌ loader-utils-1.4.0.tgz (Vulnerable Library)
-
sass-loader-8.0.2.tgz (Root Library)
- ❌ loader-utils-1.4.0.tgz (Vulnerable Library)
Reachability Analysis
This vulnerability is potentially reachable:
Vulnerability Details
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.
Publish Date: Oct 12, 2022 12:00 AM
URL: CVE-2022-37601
Threat Assessment
Exploit Maturity:Not Defined
EPSS:24.6%
Score: 9.3
Suggested Fix
Type: Upgrade version
Origin: GHSA-76p3-8jx3-jpfq
Release Date: Oct 12, 2022 12:00 AM
Fix Resolution : loader-utils - 2.0.3,loader-utils - 1.4.1
🔴CVE-2022-37599
Vulnerable Library - loader-utils-1.4.0.tgz
utils for webpack loaders
Library home page: https://registry.npmjs.org/loader-utils/-/loader-utils-1.4.0.tgz
Dependency Hierarchy:
-
babel-loader-8.1.0.tgz (Root Library)
- ❌ loader-utils-1.4.0.tgz (Vulnerable Library)
-
postcss-loader-3.0.0.tgz (Root Library)
- ❌ loader-utils-1.4.0.tgz (Vulnerable Library)
-
mini-css-extract-plugin-0.11.3.tgz (Root Library)
- ❌ loader-utils-1.4.0.tgz (Vulnerable Library)
-
html-webpack-plugin-4.5.0.tgz (Root Library)
- ❌ loader-utils-1.4.0.tgz (Vulnerable Library)
-
sass-loader-8.0.2.tgz (Root Library)
- ❌ loader-utils-1.4.0.tgz (Vulnerable Library)
Reachability Analysis
This vulnerability is potentially reachable:
Vulnerability Details
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js.
Publish Date: Oct 11, 2022 12:00 AM
URL: CVE-2022-37599
Threat Assessment
Exploit Maturity:Not Defined
EPSS:7.1000004%
Score: 8.7
Suggested Fix
Type: Upgrade version
Origin: https://osv.dev/vulnerability/CVE-2022-37599
Release Date: Oct 11, 2022 12:00 AM
Fix Resolution : https://github.com/webpack/loader-utils.git - no_fix,loader-utils - 1.4.2,loader-utils - 2.0.4,loader-utils - 3.2.1
🔴CVE-2022-37603
Vulnerable Library - loader-utils-1.4.0.tgz
utils for webpack loaders
Library home page: https://registry.npmjs.org/loader-utils/-/loader-utils-1.4.0.tgz
Dependency Hierarchy:
-
babel-loader-8.1.0.tgz (Root Library)
- ❌ loader-utils-1.4.0.tgz (Vulnerable Library)
-
postcss-loader-3.0.0.tgz (Root Library)
- ❌ loader-utils-1.4.0.tgz (Vulnerable Library)
-
mini-css-extract-plugin-0.11.3.tgz (Root Library)
- ❌ loader-utils-1.4.0.tgz (Vulnerable Library)
-
html-webpack-plugin-4.5.0.tgz (Root Library)
- ❌ loader-utils-1.4.0.tgz (Vulnerable Library)
-
sass-loader-8.0.2.tgz (Root Library)
- ❌ loader-utils-1.4.0.tgz (Vulnerable Library)
Reachability Analysis
This vulnerability is potentially reachable:
Vulnerability Details
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the url variable in interpolateName.js.
Publish Date: Oct 14, 2022 12:00 AM
URL: CVE-2022-37603
Threat Assessment
Exploit Maturity:Not Defined
EPSS:1.7%
Score: 8.7
Suggested Fix
Type: Upgrade version
Origin: GHSA-3rfm-jhwj-7488
Release Date: Oct 14, 2022 12:00 AM
Fix Resolution : loader-utils - 1.4.2,loader-utils - 3.2.1,loader-utils - 2.0.4
📂 Vulnerable Library - postcss-loader-3.0.0.tgz
PostCSS loader for webpack
Findings
Details
🟣CVE-2022-37601
Vulnerable Library - loader-utils-1.4.0.tgz
utils for webpack loaders
Library home page: https://registry.npmjs.org/loader-utils/-/loader-utils-1.4.0.tgz
Dependency Hierarchy:
babel-loader-8.1.0.tgz (Root Library)
postcss-loader-3.0.0.tgz (Root Library)
mini-css-extract-plugin-0.11.3.tgz (Root Library)
html-webpack-plugin-4.5.0.tgz (Root Library)
sass-loader-8.0.2.tgz (Root Library)
Reachability Analysis
This vulnerability is potentially reachable:
Vulnerability Details
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.
Publish Date: Oct 12, 2022 12:00 AM
URL: CVE-2022-37601
Threat Assessment
Exploit Maturity:Not Defined
EPSS:24.6%
Score: 9.3
Suggested Fix
Type: Upgrade version
Origin: GHSA-76p3-8jx3-jpfq
Release Date: Oct 12, 2022 12:00 AM
Fix Resolution : loader-utils - 2.0.3,loader-utils - 1.4.1
🔴CVE-2022-37599
Vulnerable Library - loader-utils-1.4.0.tgz
utils for webpack loaders
Library home page: https://registry.npmjs.org/loader-utils/-/loader-utils-1.4.0.tgz
Dependency Hierarchy:
babel-loader-8.1.0.tgz (Root Library)
postcss-loader-3.0.0.tgz (Root Library)
mini-css-extract-plugin-0.11.3.tgz (Root Library)
html-webpack-plugin-4.5.0.tgz (Root Library)
sass-loader-8.0.2.tgz (Root Library)
Reachability Analysis
This vulnerability is potentially reachable:
Vulnerability Details
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js.
Publish Date: Oct 11, 2022 12:00 AM
URL: CVE-2022-37599
Threat Assessment
Exploit Maturity:Not Defined
EPSS:7.1000004%
Score: 8.7
Suggested Fix
Type: Upgrade version
Origin: https://osv.dev/vulnerability/CVE-2022-37599
Release Date: Oct 11, 2022 12:00 AM
Fix Resolution : https://github.com/webpack/loader-utils.git - no_fix,loader-utils - 1.4.2,loader-utils - 2.0.4,loader-utils - 3.2.1
🔴CVE-2022-37603
Vulnerable Library - loader-utils-1.4.0.tgz
utils for webpack loaders
Library home page: https://registry.npmjs.org/loader-utils/-/loader-utils-1.4.0.tgz
Dependency Hierarchy:
babel-loader-8.1.0.tgz (Root Library)
postcss-loader-3.0.0.tgz (Root Library)
mini-css-extract-plugin-0.11.3.tgz (Root Library)
html-webpack-plugin-4.5.0.tgz (Root Library)
sass-loader-8.0.2.tgz (Root Library)
Reachability Analysis
This vulnerability is potentially reachable:
Vulnerability Details
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the url variable in interpolateName.js.
Publish Date: Oct 14, 2022 12:00 AM
URL: CVE-2022-37603
Threat Assessment
Exploit Maturity:Not Defined
EPSS:1.7%
Score: 8.7
Suggested Fix
Type: Upgrade version
Origin: GHSA-3rfm-jhwj-7488
Release Date: Oct 14, 2022 12:00 AM
Fix Resolution : loader-utils - 1.4.2,loader-utils - 3.2.1,loader-utils - 2.0.4