Input validation error in qs - CVE-2017-1000048

 

Input validation error in qs - CVE-2017-1000048

Published: July 17, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU38700
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-1000048
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

the web framework using ljharb's qs module older than v6.3.2, v6.2.3, v6.1.2, and v6.0.4 is vulnerable to a DoS. A malicious user can send a evil request to cause the web framework crash.


Affected software

qs
IBM Engineering Requirements Quality Assistant
IBM Watson Machine Learning Accelerator
IBM Planning Analytics Workspace
Netcool Operations Insight
IBM Security Verify Governance
rh-nodejs6-nodejs-qs (Red Hat package)

How to mitigate CVE-2017-1000048

Install update from vendor's website.

Netcool Operations Insight - update to 1.6.7
IBM Planning Analytics Workspace - update to 2.0.93
rh-nodejs6-nodejs-qs (Red Hat package) - addressed in versions 6.2.3-1.el6, 6.2.3-1.el7
IBM Security Verify Governance - update to 10.0.2

External References

Related Security Bulletins