QID 983489
QID 983489: Nodejs (npm) Security Update for qs (GHSA-crvj-3gj9-gm2p)
Withdrawn, accidental duplicate publish.
The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-crvj-3gj9-gm2p for updates pertaining to this vulnerability.
Vendor References
- GHSA-crvj-3gj9-gm2p -
github.com/advisories/GHSA-crvj-3gj9-gm2p
CVEs related to QID 983489
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-crvj-3gj9-gm2p | qs |
|