In webpack-subresource-integrity before version 1.5.1, all dynamically loaded chunks receive an invalid integrity hash that is ignored by the browser, and therefore the browser cannot validate their integrity. This removes the additional level of protection offered by SRI for such chunks. Top-level chunks are unaffected. This issue is patched in version 1.5.1.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2020-10-19T20:10:18

Updated: 2024-08-04T13:15:19.047Z

Reserved: 2020-06-25T00:00:00

Link: CVE-2020-15262

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-10-19T20:15:12.667

Modified: 2021-11-18T16:19:14.013

Link: CVE-2020-15262

cve-icon Redhat

No data.