CVE-2023-28154 | Webpack up to 5.75.x Magic Comment ImportParserPlugin.js access control (EUVD-2023-1030)
A vulnerability was found in Webpack up to 5.75.x. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file ImportParserPlugin.js of the component Magic Comment Handler. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2023-28154. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.