Описание
the web framework using ljharb's qs module older than v6.3.2, v6.2.3, v6.1.2, and v6.0.4 is vulnerable to a DoS. A malicious user can send a evil request to cause the web framework crash.
It was found that ljharb's qs module for Node.js did not properly parse query strings. An attacker could send a specially crafted query that overwrites the resulting object's prototype properties (such as toString() or hasOwnProperty()), resulting in a denial of service when the overwritten function would be executed.
Отчет
Red Hat Quay include nodejs-qs as a build time dependency. Nodejs-qs is used by protractor for testing as build time, and is not included as runtime.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Mobile Application Platform 4 | fh-mbaas | Will not fix | ||
| Red Hat Mobile Application Platform 4 | fh-ngui | Will not fix | ||
| Red Hat Mobile Application Platform 4 | fh-scm | Will not fix | ||
| Red Hat Mobile Application Platform 4 | fh-statsd | Will not fix | ||
| Red Hat Mobile Application Platform 4 | fh-supercore | Will not fix | ||
| Red Hat OpenShift Enterprise 3 | nodejs-qs | Under investigation | ||
| Red Hat Quay 3 | quay/quay-rhel8 | Not affected | ||
| Red Hat Software Collections | rh-nodejs4-nodejs-qs | Not affected | ||
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-nodejs6-nodejs-qs | Fixed | RHSA-2017:2672 | 07.09.2017 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | rh-nodejs6-nodejs-qs | Fixed | RHSA-2017:2672 | 07.09.2017 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
the web framework using ljharb's qs module older than v6.3.2, v6.2.3, v6.1.2, and v6.0.4 is vulnerable to a DoS. A malicious user can send a evil request to cause the web framework crash.
the web framework using ljharb's qs module older than v6.3.2, v6.2.3, v6.1.2, and v6.0.4 is vulnerable to a DoS. A malicious user can send a evil request to cause the web framework crash.
EPSS
5.3 Medium
CVSS3