QID 981009
QID 981009: Nodejs (npm) Security Update for qs (GHSA-jjv7-qpx3-h62q)
Versions prior to 1.0 of `qs` are affected by a denial of service condition. This condition is triggered by parsing a crafted string that deserializes into very large sparse arrays, resulting in the process running out of memory and eventually crashing.
## Recommendation
Update to version 1.0.0 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-jjv7-qpx3-h62q for updates pertaining to this vulnerability.
Vendor References
- GHSA-jjv7-qpx3-h62q -
github.com/advisories/GHSA-jjv7-qpx3-h62q
CVEs related to QID 981009
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-jjv7-qpx3-h62q | qs |
|