Back to search
CVE-2023-28154
Published: Mar 13, 2023
Modified: Feb 27, 2025
PUBLISHED
Description
Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
FEDORA-2023-4d546e6b4b
vendor-advisory
FEDORA-2023-cb2e422088
vendor-advisory
FEDORA-2023-5993ffa09a
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now