-
Notifications
You must be signed in to change notification settings - Fork 0
Description
Vulnerable Package issue exists @ Npm-qs-6.0.0 in branch master
the web framework using ljharb's qs module older than v6.3.2, v6.2.3, v6.1.2, and v6.0.4 is vulnerable to a DoS. A malicious user can send a evil request to cause the web framework crash.
Namespace: cyates-checkmarx
Repository: JVL
Repository Url: https://github.com/cyates-checkmarx/JVL
CxAST-Project: cyates-checkmarx/JVL
CxAST platform scan: 7b012027-b586-4987-b934-7a017732de85
Branch: master
Application: JVL
Severity: HIGH
State: NOT_IGNORED
Status: RECURRENT
CWE: CWE-20
Additional Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: NONE
Availability impact: HIGH
Remediation Upgrade Recommendation: 6.0.4
References
Commit
Commit
Advisory
Advisory
Issue
Pull request
Pull request