7.5

CVE-2017-1000048

the web framework using ljharb's qs module older than v6.3.2, v6.2.3, v6.1.2, and v6.0.4 is vulnerable to a DoS. A malicious user can send a evil request to cause the web framework crash.

Data is provided by the National Vulnerability Database (NVD)
Qs ProjectQs Version1.0.0
Qs ProjectQs Version1.0.1
Qs ProjectQs Version1.0.2
Qs ProjectQs Version1.1.0
Qs ProjectQs Version1.2.0
Qs ProjectQs Version1.2.1
Qs ProjectQs Version2.3.1
Qs ProjectQs Version2.3.2
Qs ProjectQs Version2.3.3
Qs ProjectQs Version2.4.0
Qs ProjectQs Version2.4.1
Qs ProjectQs Version2.4.2
Qs ProjectQs Version3.0.0
Qs ProjectQs Version3.1.0
Qs ProjectQs Version4.0.0
Qs ProjectQs Version5.0.0
Qs ProjectQs Version5.1.0
Qs ProjectQs Version5.2.0
Qs ProjectQs Version5.2.1
Qs ProjectQs Version6.0.0
Qs ProjectQs Version6.0.1
Qs ProjectQs Version6.0.2
Qs ProjectQs Version6.0.3
Qs ProjectQs Version6.1.0
Qs ProjectQs Version6.1.1
Qs ProjectQs Version6.2.0
Qs ProjectQs Version6.2.1
Qs ProjectQs Version6.2.2
Qs ProjectQs Version6.3.0
Qs ProjectQs Version6.3.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.53% 0.664
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.