PT-2022-12260 · Qs+1 · Qs+1
Published
2022-03-17
·
Updated
2022-05-17
·
CVE-2021-44907
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
qs versions up to 6.8.0
Description
A Denial of Service issue exists due to insufficient sanitization of properties in the
gs.parse function. The merge() function allows assigning properties on an array in the query, which can cause unexpected behavior if not properly checked by the user with Array.isArray().Recommendations
For versions up to 6.8.0, consider updating to a version where this issue is resolved, as the current version may cause unexpected behavior due to the lack of proper sanitization in the
gs.parse function.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Suse
Qs