Vulnerability Description
The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string representing a deeply nested object will block the event loop for long periods of time. An attacker could leverage this to cause a temporary denial-of-service condition, for example, in a web application, other requests would not be processed while this blocking is occurring.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qs Project | Qs | < 1.0.0 |
Related Weaknesses (CWE)
References
- https://nodesecurity.io/advisories/28Third Party Advisory
- https://nodesecurity.io/advisories/28Third Party Advisory
FAQ
What is CVE-2014-10064?
CVE-2014-10064 is a vulnerability with a CVSS score of 7.5 (HIGH). The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string representing a deeply nested object will block the event loop for long periods of ti...
How severe is CVE-2014-10064?
CVE-2014-10064 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-10064?
Check the references section above for vendor advisories and patch information. Affected products include: Qs Project Qs.