Description
In webpack-subresource-integrity before version 1.5.1, all dynamically loaded chunks receive an invalid integrity hash that is ignored by the browser, and therefore the browser cannot validate their integrity. This removes the additional level of protection offered by SRI for such chunks. Top-level chunks are unaffected. This issue is patched in version 1.5.1.
Published: 2020-10-19
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-1406 In webpack-subresource-integrity before version 1.5.1, all dynamically loaded chunks receive an invalid integrity hash that is ignored by the browser, and therefore the browser cannot validate their integrity. This removes the additional level of protection offered by SRI for such chunks. Top-level chunks are unaffected. This issue is patched in version 1.5.1.
Github GHSA Github GHSA GHSA-4fc4-chg7-h8gh Unprotected dynamically loaded chunks
History

No history.

Subscriptions

Webpack-subresource-integrity Project Webpack-subresource-integrity
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-04T13:15:19.047Z

Reserved: 2020-06-25T00:00:00.000Z

Link: CVE-2020-15262

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-10-19T20:15:12.667

Modified: 2024-11-21T05:05:13.333

Link: CVE-2020-15262

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses