Access Restriction Bypass Affecting webpack-subresource-integrity package, versions >=1.5.0 <1.5.1


Severity

Recommended
0.0
low
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.1% (43rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Access Restriction Bypass vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-WEBPACKSUBRESOURCEINTEGRITY-1019475
  • published20 Oct 2020
  • disclosed19 Oct 2020
  • creditUnknown

Introduced: 19 Oct 2020

CVE-2020-15262  (opens in a new tab)
CWE-284  (opens in a new tab)

How to fix?

Upgrade webpack-subresource-integrity to version 1.5.1 or higher.

Overview

webpack-subresource-integrity is a Webpack plugin for enabling Subresource Integrity

Affected versions of this package are vulnerable to Access Restriction Bypass. All dynamically loaded chunks receive an invalid integrity hash that is ignored by the browser, and therefore the browser cannot validate their integrity. This removes the additional level of protection offered by SRI for such chunks. Top-level chunks are unaffected.

References

CVSS Scores

version 3.1