Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2022-24999 | qs:6.2.3 (CWE-0) #84

Open
ckalpakoglu opened this issue Jan 2, 2023 · 0 comments
Open

CVE-2022-24999 | qs:6.2.3 (CWE-0) #84

ckalpakoglu opened this issue Jan 2, 2023 · 0 comments
Assignees
Labels
bug Something isn't working KONDUKTO

Comments

@ckalpakoglu
Copy link

A high severity vulnerability has been discovered in your project.

Project Name: kondukto-ui-vue

Scanner Name: dependabot

File: package-lock.json

Packages:

  • qs:6.2.3

References:

Tool Description: Summary: qs vulnerable to Prototype Pollution.
Description: qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated remote attacker can place the attack payload in the query string of the URL that is used to visit the application, such as a[proto]=b&a[proto]&a[length]=100000000. The fix was backported to qs 6.9.7, 6.8.3, 6.7.3, 6.6.1, 6.5.3, 6.4.1, 6.3.3, and 6.2.4 (and therefore Express 4.17.3, which has "deps: [email protected]" in its release description, is not vulnerable).

@ckalpakoglu ckalpakoglu added bug Something isn't working KONDUKTO labels Jan 2, 2023
@ckalpakoglu ckalpakoglu self-assigned this Jan 2, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working KONDUKTO
Projects
None yet
Development

No branches or pull requests

1 participant