In webpack-subresource-integrity before version 1.5.1, all dynamically loaded chunks receive an invalid integrity hash that is ignored by the browser, and therefore the browser cannot validate their integrity. This removes the additional level of protection offered by SRI for such chunks. Top-level chunks are unaffected. This issue is patched in version 1.5.1.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2020-10-19T20:10:18

Updated: 2020-10-19T20:10:17

Reserved: 2020-06-25T00:00:00


Link: CVE-2020-15262

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-10-19T20:15:12.667

Modified: 2021-11-18T16:19:14.013


Link: CVE-2020-15262

JSON object: View

cve-icon Redhat Information

No data.

CWE