Asymmetric denial of service - ReDoS In node-loader-utils
Description
loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS) A regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils via the resourcePath variable in interpolateName.js. A badly or maliciously formed string could be used to send crafted requests that cause a system to crash or take a disproportional amount of time to process. This issue has been patched in versions 1.4.2, 2.0.4 and 3.2.1.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 2.0.4-1 | ||
debian 13 | 2.0.4-1 | ||
debian 11 | 2.0.0-1+deb11u1 | ||
debian 14 | 2.0.4-1 | ||
npm | 1.4.2, 2.0.4, 3.2.1 | ||
rpm rhel7 | - | - | |
rpm rhel8 | - | - | |
rpm rhel8 | - | - | |
rpm rhel8 | - | - | |
rpm rhel6 | - | - |
1-10 of 12
10
Aliases
References