PT-2018-4153 · Qs · Qs

Published

2018-05-31

·

Updated

2019-10-09

·

CVE-2014-10064

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions qs versions prior to 1.0.0
Description The issue allows an attacker to cause a temporary denial-of-service condition by parsing a string representing a deeply nested object, which can block the event loop for long periods of time. This can be particularly problematic in web applications, where other requests would not be processed while this blocking is occurring.
Recommendations Update to version 1.0.0 or later. As a temporary workaround, consider restricting the parsing of deeply nested JSON strings to minimize the risk of exploitation.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-10064
GHSA-F9CM-P3W6-XVR3

Affected Products

Qs