CVE-2020-15262
LOWWebpack-subresource-integrity <1.5.1 - Info Disclosure
Title source: llmDescription
In webpack-subresource-integrity before version 1.5.1, all dynamically loaded chunks receive an invalid integrity hash that is ignored by the browser, and therefore the browser cannot validate their integrity. This removes the additional level of protection offered by SRI for such chunks. Top-level chunks are unaffected. This issue is patched in version 1.5.1.
References (3)
Core 3
Core References
Third Party Advisory x_refsource_confirm
https://github.com/waysact/webpack-subresource-integrity/security/advisories/GHSA-4fc4-chg7-h8gh
Third Party Advisory x_refsource_misc
https://github.com/waysact/webpack-subresource-integrity/issues/131
Patch, Third Party Advisory x_refsource_misc
https://github.com/waysact/webpack-subresource-integrity/commit/3d7090c08c333fcfb10ad9e2d6cf72e2acb7d87f
Scores
CVSS v3
3.7
EPSS
0.0051
EPSS Percentile
39.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-345
Status
published
Products (2)
npm/webpack-subresource-integrity
0 - 1.5.1npm
webpack-subresource-integrity_project/webpack-subresource-integrity
< 1.5.1
Published
Oct 19, 2020
Tracked Since
Feb 18, 2026