Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FP]: webpack@4.46.0 CVE-2023-28154 #5933

Closed
aliu-vmware opened this issue Sep 13, 2023 · 4 comments
Closed

[FP]: webpack@4.46.0 CVE-2023-28154 #5933

aliu-vmware opened this issue Sep 13, 2023 · 4 comments
Labels
FP Report npm ossindex Label for issues that relate to the OSSIndex API

Comments

@aliu-vmware
Copy link

Package URl

pkg:npm/webpack@4.46.0

CPE

cpe:2.3:a:webpack.js:webpack:4.46.0:::::::*

CVE

CVE-2023-28154

ODC Integration

None

ODC Version

8.4.0

Description

CVE reports "Webpack 5 before 5.76.0", but the proper range is 5.0.0 -> 5.76.0, Webpack 4 is unaffected.

See: webpack/webpack#16500 (comment)

@aliu-vmware aliu-vmware changed the title [FP]: [FP]: webpack@4.46.0 CVE-2023-28154 Sep 13, 2023
@github-actions
Copy link
Contributor

Npm Coordinates

npm -i webpack@4.46.0

Suppression rule:

<suppress base="true">
   <notes><![CDATA[
   FP per issue #5933
   ]]></notes>
   <packageUrl regex="true">^pkg:npm/webpack@.*$</packageUrl>
   <cpe>cpe:/a:webpack.js:webpack</cpe>
</suppress>

Link to test results: https://github.com/jeremylong/DependencyCheck/actions/runs/6178615557

@github-actions github-actions bot added the npm label Sep 13, 2023
@github-actions
Copy link
Contributor

Npm Coordinates

npm -i webpack@4.46.0

Suppression rule:

<suppress base="true">
   <notes><![CDATA[
   FP per issue #5933
   ]]></notes>
   <packageUrl regex="true">^pkg:npm/webpack@.*$</packageUrl>
   <cpe>cpe:/a:webpack.js:webpack</cpe>
</suppress>

Link to test results: https://github.com/jeremylong/DependencyCheck/actions/runs/6178621246

@aikebah aikebah added the ossindex Label for issues that relate to the OSSIndex API label Sep 14, 2023
@aikebah
Copy link
Collaborator

aikebah commented Sep 14, 2023

4.46 is currently labeled as vulnerable to the CVE. This is either a lack of version-info linking at Sonatype, or their researchers consider older versions vulnerable as well. You should raise your concerns with Sonatype. See https://ossindex.sonatype.org/component/pkg:npm/webpack@4.46.0

@aliu-vmware
Copy link
Author

Thanks, I'll do that.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
FP Report npm ossindex Label for issues that relate to the OSSIndex API
Projects
None yet
Development

No branches or pull requests

2 participants