CVE-2014-10064
published 2018-05-31CVE-2014-10064: The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string representing a deeply nested object will…
PriorityP335high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
1.29%
67.2th percentile
The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string representing a deeply nested object will block the event loop for long periods of time. An attacker could leverage this to cause a temporary denial-of-service condition, for example, in a web application, other requests would not be processed while this blocking is occurring.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-qs | < node-qs 2.2.4-1 (bookworm) | node-qs 2.2.4-1 (bookworm) |
| hackerone | qs_node_module | — | — |
| qs_project | qs | < 1.0.0 | 1.0.0 |
| qs_project | qs | >= 0 < 1.0.0 | 1.0.0 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Denial-of-Service Extended Event Loop Blocking in qs
ghsa·2018-10-09
CVE-2014-10064 [HIGH] CWE-400 Denial-of-Service Extended Event Loop Blocking in qs
Denial-of-Service Extended Event Loop Blocking in qs
Versions prior to 1.0.0 of `qs` are affected by a denial of service vulnerability that results from excessive recursion in parsing a deeply nested JSON string.
## Recommendation
Update to version 1.0.0 or later
OSV
Denial-of-Service Extended Event Loop Blocking in qs
osv·2018-10-09
CVE-2014-10064 [HIGH] Denial-of-Service Extended Event Loop Blocking in qs
Denial-of-Service Extended Event Loop Blocking in qs
Versions prior to 1.0.0 of `qs` are affected by a denial of service vulnerability that results from excessive recursion in parsing a deeply nested JSON string.
## Recommendation
Update to version 1.0.0 or later
OSV
CVE-2014-10064: The qs module before 1
osv·2018-05-31·CVSS 7.5
CVE-2014-10064 [HIGH] CVE-2014-10064: The qs module before 1
The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string representing a deeply nested object will block the event loop for long periods of time. An attacker could leverage this to cause a temporary denial-of-service condition, for example, in a web application, other requests would not be processed while this blocking is occurring.
Debian
CVE-2014-10064: node-qs - The qs module before 1.0.0 does not have an option or default for specifying obj...
vendor_debian·2014·CVSS 7.5
CVE-2014-10064 [HIGH] CVE-2014-10064: node-qs - The qs module before 1.0.0 does not have an option or default for specifying obj...
The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string representing a deeply nested object will block the event loop for long periods of time. An attacker could leverage this to cause a temporary denial-of-service condition, for example, in a web application, other requests would not be processed while this blocking is occurring.
Scope: local
bookworm: resolved (fixed in 2.2.4-1)
bullseye: resolved (fixed in 2.2.4-1)
forky: resolved (fixed in 2.2.4-1)
sid: resolved (fixed in 2.2.4-1)
trixie: resolved (fixed in 2.2.4-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-05-31
Published