Prototype pollution in webpack loader-utils
Critical severity
GitHub Reviewed
Published
Oct 13, 2022
to the GitHub Advisory Database
•
Updated Sep 21, 2023
Description
Published by the National Vulnerability Database
Oct 12, 2022
Published to the GitHub Advisory Database
Oct 13, 2022
Reviewed
Nov 4, 2022
Last updated
Sep 21, 2023
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils prior to version 2.0.3 via the name variable in parseQuery.js.
References