CVE-2023-28154
Published on: Not Yet Published
Last Modified on: 04/22/2023 03:15:00 AM UTC
Certain versions of Webpack from Webpack.js contain the following vulnerability:
Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.
- CVE-2023-28154 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
CVSS3 Score: 9.8 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
[SECURITY] Fedora 36 Update: pcs-0.11.5-2.fc36 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
[SECURITY] Fedora 38 Update: pcs-0.11.5-2.fc38 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
refactor: avoid cross-realm objects by Jack-Works · Pull Request #16500 · webpack/webpack · GitHub | github.com text/html |
![]() |
[SECURITY] Fedora 37 Update: pcs-0.11.5-2.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
Comparing v5.75.0...v5.76.0 · webpack/webpack · GitHub | github.com text/html |
![]() |
Related QID Numbers
- 160538 Oracle Enterprise Linux Security Update for pcs (ELSA-2023-12235)
- 241306 Red Hat Update for pcs (RHSA-2023:1591)
- 283923 Fedora Security Update for pcs (FEDORA-2023-5993ffa09a)
- 283924 Fedora Security Update for pcs (FEDORA-2023-cb2e422088)
- 940973 AlmaLinux Security Update for pcs (ALSA-2023:1591)
- 960901 Rocky Linux Security Update for pcs (RLSA-2023:1591)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Webpack.js | Webpack | All | All | All | All |
- cpe:2.3:a:webpack.js:webpack:*:*:*:*:*:node.js:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-28154 : Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles… twitter.com/i/web/status/1… | 2023-03-13 01:06:25 |
![]() |
CVE-2023-28154 | 2023-03-13 02:38:47 |