Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

loader-utils dependency v2 is vulnerable and should be updated to v3: CVE-2022-37599 #954

Closed
Akkora opened this issue Oct 13, 2022 · 7 comments · Fixed by #942
Closed

loader-utils dependency v2 is vulnerable and should be updated to v3: CVE-2022-37599 #954

Akkora opened this issue Oct 13, 2022 · 7 comments · Fixed by #942

Comments

@Akkora
Copy link

Akkora commented Oct 13, 2022

Hello,
as the webpack loader-utils v2 are vulnerable, we get issues when installing babel-loader in current version 8.2.5. Could you please provide an update with the upgraded to v3 loader-utils package?

Link to more vulnerability details
https://nvd.nist.gov/vuln/detail/CVE-2022-37599

@SymbioticKilla
Copy link

@nicolo-ribaudo Any chance to get updated version soon?

@Shivam60
Copy link

Hey. Any guidance how we can help over this ?

@mostja01
Copy link

I think this issue might be resolved in PR #942

@Shivam60
Copy link

That is great to hear

@jamesxu0816
Copy link

Is there any progress on this issue? Looks like it impacts most of react applications. Can someone help to fix the security issue? Thanks.

@JLHwung
Copy link
Contributor

JLHwung commented Oct 23, 2022

loader-utils@3 is still affected by one CVE: webpack/loader-utils#215

We will remove loader-utils in babel-loader@9 and drop webpack 4 support. See #942.

@jamesxu0816
Copy link

Great. Thanks. We are expecting this upgrade to fix loader-utils security issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

6 participants