GHSA-crvj-3gj9-gm2p

Suggest an improvement
Source
https://github.com/advisories/GHSA-crvj-3gj9-gm2p
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-crvj-3gj9-gm2p/GHSA-crvj-3gj9-gm2p.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-crvj-3gj9-gm2p
Withdrawn
2020-06-16T21:32:53Z
Published
2018-10-09T00:44:29Z
Modified
2020-06-16T21:43:40Z
Summary
High severity vulnerability that affects qs
Details

Withdrawn, accidental duplicate publish.

The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.

Database specific
{
    "cwe_ids":  [],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-06-16T21:32:53Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / qs

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-crvj-3gj9-gm2p/GHSA-crvj-3gj9-gm2p.json"