GHSA-gqgv-6jq5-jjj9

    Dashboard / Vulnerabilities / GHSA-gqgv-6jq5-jjj9

    GHSA-gqgv-6jq5-jjj9

    Published: 30 Apr 2020Last Modified: 8 Nov 2023

    Summary: Prototype Pollution Protection Bypass in qs

    Details: Affected version of `qs` are vulnerable to Prototype Pollution because it is possible to bypass the protection. The `qs.parse` function fails to properly prevent an object's prototype to be altered when parsing arbitrary input. Input containing `[` or `]` may bypass the prototype pollution protection and alter the Object prototype. This allows attackers to override properties that will exist in all objects, which may lead to Denial of Service or Remote Code Execution in specific circumstances. ## Recommendation Upgrade to 6.0.4, 6.1.2, 6.2.3, 6.3.2 or later.

    Affected packages

    Package

    Name: qs

    Purl: pkg:npm/qs

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -6.0.4

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-gqgv-6jq5-jjj9 | CVE-DB