Skip to content

[🐸 Frogbot] Update version of webpack to 5.104.1#547

Open
github-actions[bot] wants to merge 1 commit into
masterfrom
frogbot-webpack-27734f7af4092b9a4ff31181599cb37f
Open

[🐸 Frogbot] Update version of webpack to 5.104.1#547
github-actions[bot] wants to merge 1 commit into
masterfrom
frogbot-webpack-27734f7af4092b9a4ff31181599cb37f

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

🚨 This automated pull request was created by Frogbot and fixes the below:

📦 Vulnerable Dependencies

Severity ID Contextual Analysis Direct Dependencies Impacted Dependency Fixed Versions
medium
Medium
CVE-2024-43788 Not Covered webpack:5.91.0
webpack-cli:4.10.0
jfrog-ide-webview:0.4.3
ts-loader:9.5.1
webpack 5.91.0 [5.94.0]

🔖 Details

Vulnerability Details

Contextual Analysis: Not Covered
Direct Dependencies: webpack:5.91.0, webpack-cli:4.10.0, jfrog-ide-webview:0.4.3, ts-loader:9.5.1
Impacted Dependency: webpack:5.91.0
Fixed Versions: [5.94.0]
CVSS V3: 6.1

Webpack is a module bundler. Its main purpose is to bundle JavaScript files for usage in a browser, yet it is also capable of transforming, bundling, or packaging just about any resource or asset. The webpack developers have discovered a DOM Clobbering vulnerability in Webpack’s AutoPublicPathRuntimeModule. The DOM Clobbering gadget in the module can lead to cross-site scripting (XSS) in web pages where scriptless attacker-controlled HTML elements (e.g., an img tag with an unsanitized name attribute) are present. Real-world exploitation of this gadget has been observed in the Canvas LMS which allows a XSS attack to happen through a javascript code compiled by Webpack (the vulnerable part is from Webpack). DOM Clobbering is a type of code-reuse attack where the attacker first embeds a piece of non-script, seemingly benign HTML markups in the webpage (e.g. through a post or comment) and leverages the gadgets (pieces of js code) living in the existing javascript code to transform it into executable code. This vulnerability can lead to cross-site scripting (XSS) on websites that include Webpack-generated files and allow users to inject certain scriptless HTML tags with improperly sanitized name or id attributes. This issue has been addressed in release version 5.94.0. All users are advised to upgrade. There are no known workarounds for this issue.


Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant