Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils prior to version 2.0.3 via the name variable in parseQuery.js.
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-37601
- https://github.com/webpack/loader-utils/issues/212
- https://github.com/webpack/loader-utils/blob/d9f4e23cf411d8556f8bac2d3bf05a6e0103b568/lib/parseQuery.js#L11
- https://github.com/webpack/loader-utils/blob/d9f4e23cf411d8556f8bac2d3bf05a6e0103b568/lib/parseQuery.js#L47
- https://github.com/webpack/loader-utils/releases/tag/v2.0.3
- https://github.com/webpack/loader-utils/pull/217
- https://github.com/webpack/loader-utils/pull/220
- https://github.com/webpack/loader-utils/releases/tag/v1.4.1
- https://github.com/advisories/GHSA-76p3-8jx3-jpfq