PT-2022-12260 · Qs+1 · Qs+1

Published

2022-03-17

·

Updated

2022-05-17

·

CVE-2021-44907

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions qs versions up to 6.8.0
Description A Denial of Service issue exists due to insufficient sanitization of properties in the gs.parse function. The merge() function allows assigning properties on an array in the query, which can cause unexpected behavior if not properly checked by the user with Array.isArray().
Recommendations For versions up to 6.8.0, consider updating to a version where this issue is resolved, as the current version may cause unexpected behavior due to the lack of proper sanitization in the gs.parse function.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-44907
OPENSUSE-SU-2022_1461-1
OPENSUSE-SU-2022_1462-1
OPENSUSE-SU-2022_1694-1
OPENSUSE-SU-2022_1717-1
SUSE-SU-2022:1459-1
SUSE-SU-2022:1461-1
SUSE-SU-2022:1462-1
SUSE-SU-2022:1466-1
SUSE-SU-2022:1694-1
SUSE-SU-2022:1717-1
SUSE-SU-2022_1717-1

Affected Products

Suse
Qs