Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38017
HistoryNov 16, 2022 - 5:59 a.m.

Prototype Pollution

2022-11-1605:59:29
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
node-loader-utils
vulnerability
parsequery function
prototype pollution
webpack loader-utils
name variable
attacker

0.01 Low

EPSS

Percentile

83.4%

node-loader-utils is vulnerable to Prototype Pollution. The vulnerability exists in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js which allows an attacker to cause a prototype pollution.