CVE-2014-7191CVE-2014-7191

Affected configuration(s):

cpe:/a:nodejs:node.js:0.10.18

Date published: 2014-10-18T21:55:21.560-04:00

Date last modified: 2017-09-07T21:29:15.590-04:00

CVSS Score: 5.0

Principal attack vector: NETWORK

Complexity:  LOW

Reference URL: http://secunia.com/advisories/62170

Summary: The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.

CategoriesUncategorised

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.