webpack JS package <= 5.75.0 - Sandbox Bypass
2023-04-11 00:00
AnonymousStrategic Overview
StatusPatched in 7.4.0
Affected PluginRestricted Site Access
Affected Version
<= 7.3.5CVSS8.3High
CVE
CVE-2023-28154Vulnerability Overview
The JS package webpack is vulnerable to Sandbox Bypass in versions up to, and including, 5.75.0 due to mishandling magic comments. Some WordPress plugins and themes use this dependency, however, are not vulnerable to exploitation.
Technical Analysis
REMEDIATION: Update to version 7.4.0, or a newer patched version --- IDENTIFIER: CWE-269 (Improper Privilege Management) The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C