xinYG / bootstrap-timepicker

[Deprecated] A simple timepicker component for Twitter Bootstrap
MIT License
0 stars 0 forks source link

CVE-2014-7191 (Medium) detected in qs-0.5.6.tgz - autoclosed #19

Closed mend-for-github-com[bot] closed 4 years ago

mend-for-github-com[bot] commented 4 years ago

CVE-2014-7191 - Medium Severity Vulnerability

Vulnerable Library - qs-0.5.6.tgz

querystring parser

Library home page: https://registry.npmjs.org/qs/-/qs-0.5.6.tgz

Path to dependency file: /tmp/ws-scm/bootstrap-timepicker/package.json

Path to vulnerable library: /tmp/ws-scm/bootstrap-timepicker/node_modules/tiny-lr/node_modules/qs/package.json

Dependency Hierarchy: - grunt-contrib-watch-0.4.4.tgz (Root Library) - tiny-lr-0.0.4.tgz - :x: **qs-0.5.6.tgz** (Vulnerable Library)

Found in HEAD commit: c92f0918f68b35842a2bf5ae212e5d75e70546e5

Vulnerability Details

The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.

Publish Date: 2014-10-19

URL: CVE-2014-7191

CVSS 2 Score Details (5.0)

Base Score Metrics not available

Suggested Fix

Type: Upgrade version

Origin: https://nvd.nist.gov/vuln/detail/CVE-2014-7191

Release Date: 2014-10-19

Fix Resolution: 1.0.0

mend-for-github-com[bot] commented 4 years ago

:heavy_check_mark: This issue was automatically closed by WhiteSource because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the WhiteSource inventory.