chore(deps): update dependency qs to v6.7.3 [security]#96
Open
renovate[bot] wants to merge 1 commit intomasterfrom
Open
chore(deps): update dependency qs to v6.7.3 [security]#96renovate[bot] wants to merge 1 commit intomasterfrom
renovate[bot] wants to merge 1 commit intomasterfrom
Conversation
193c20d to
2f319d2
Compare
2f319d2 to
7190cc8
Compare
7190cc8 to
a58bf91
Compare
a58bf91 to
eac8eff
Compare
eac8eff to
4df3610
Compare
4df3610 to
3e9393f
Compare
3e9393f to
a4cc519
Compare
a4cc519 to
0ce4633
Compare
0ce4633 to
933b40b
Compare
933b40b to
45b365c
Compare
45b365c to
3276ef6
Compare
3276ef6 to
3d87d52
Compare
3d87d52 to
23f74db
Compare
23f74db to
31c8ac4
Compare
31c8ac4 to
13be348
Compare
dd75a89 to
30e28a0
Compare
30e28a0 to
23ff122
Compare
23ff122 to
52ca78f
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
6.7.0→6.7.3qs vulnerable to Prototype Pollution
CVE-2022-24999 / GHSA-hrpp-h998-j3pp
More information
Details
qs before 6.10.3 allows attackers to cause a Node process hang because an
__ proto__key can be used. In many typical web framework use cases, an unauthenticated remote attacker can place the attack payload in the query string of the URL that is used to visit the application, such asa[__proto__]=b&a[__proto__]&a[length]=100000000. The fix was backported to qs 6.9.7, 6.8.3, 6.7.3, 6.6.1, 6.5.3, 6.4.1, 6.3.3, and 6.2.4.Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
ljharb/qs (qs)
v6.7.3Compare Source
parse: ignore__proto__keys (#428)stringify: avoid encoding arrayformat comma whenencodeValuesOnly = true(#424)stringify: avoid relying on a globalundefined(#427)nycfor coveragev6.7.2Compare Source
v6.7.1Compare Source
parse: Fix parsing array from object withcommatrue (#359)parse: with comma true, handle field that holds an array of arrays (#335)parse: with comma true, do not split non-string values (#334)parse: throw a TypeError instead of an Error for bad charset (#349)formats: tiny bit of cleanup.fundingfieldeslint,@ljharb/eslint-config,tape,safe-publish-latest,evalmd,iconv-lite,mkdirp,object-inspect,browserifyparse: add passingarrayFormattestsBuffer.fromin node v5.0-v5.9 and v4.0-v4.4 requires a TypedArraydepth=0anddepth=falsebehavior, both current and intuitive/intendedeclintinstead ofeditorconfig-toolsConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.