Asymmetric denial of service - ReDoS In loader-utils
Description
loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS) via url variable A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the url variable in interpolateName.js. A badly or maliciously formed string could be used to send crafted requests that cause a system to crash or take a disproportional amount of time to process. This issue has been patched in versions 1.4.2, 2.0.4 and 3.2.1.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
npm | 1.4.2, 2.0.4, 3.2.1 | ||
debian 11 | 2.0.0-1+deb11u1 | ||
debian 12 | 2.0.4-1 | ||
debian 13 | 2.0.4-1 | ||
debian 14 | 2.0.4-1 | ||
rpm rhel8 | - | - | |
rpm rhel6 | - | - | |
rpm rhel7 | - | - | |
rpm rhel8 | - | - | |
rpm rhel8 | - | - |
1-10 of 11
10
Aliases
References