CVE-2022-37601: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
(updated )
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils 2.0.0 via the name variable in parseQuery.js.
References
- github.com/webpack/loader-utils/blob/d9f4e23cf411d8556f8bac2d3bf05a6e0103b568/lib/parseQuery.js
- github.com/webpack/loader-utils/blob/d9f4e23cf411d8556f8bac2d3bf05a6e0103b568/lib/parseQuery.js
- github.com/webpack/loader-utils/issues/212
- github.com/webpack/loader-utils/issues/218
- nvd.nist.gov/vuln/detail/CVE-2022-37601
Detect and mitigate CVE-2022-37601 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →