PT-2018-4153 · Qs · Qs

Publicado

2018-05-31

·

Atualizado

2019-10-09

·

CVE-2014-10064

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions qs versions prior to 1.0.0
Description The issue allows an attacker to cause a temporary denial-of-service condition by parsing a string representing a deeply nested object, which can block the event loop for long periods of time. This can be particularly problematic in web applications, where other requests would not be processed while this blocking is occurring.
Recommendations Update to version 1.0.0 or later. As a temporary workaround, consider restricting the parsing of deeply nested JSON strings to minimize the risk of exploitation.

Correção

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-10064
GHSA-F9CM-P3W6-XVR3

Produtos afetados

Qs