Uploaded image for project: 'Apache Cordova'
  1. Apache Cordova
  2. CB-7736

Vulnerability in qs dependency

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Critical
    • Resolution: Fixed
    • 3.6.0
    • None
    • cordova-cli
    • None

    Description

      There is a very well documented vulnerability issue in the qs module that comes as a dependency in request in cordova-cli

      https://nodesecurity.io/advisories/qs_dos_memory_exhaustion

      Here the tree of modules
      cordova@3.5.0-0.2.6
      ┬ cordova-lib@0.21.6
      ├─┬ npm@1.3.4
      │ └─┬ request@2.21.0
      │ └── qs@0.6.5
      └─┬ request@2.22.0
      └── qs@0.6.6

      Even though the tree says it is in a Cordova 3.5.0, the same versions are found in 3.6.3

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              sosah.victor Victor Adrian Sosa Herrera
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: