{"id":"GHSA-crvj-3gj9-gm2p","summary":"High severity vulnerability that affects qs","details":"Withdrawn, accidental duplicate publish.\n\nThe qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.","modified":"2020-06-16T21:43:40Z","published":"2018-10-09T00:44:29Z","withdrawn":"2020-06-16T21:32:53Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-06-16T21:32:53Z","nvd_published_at":null,"cwe_ids":[],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-7191"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-crvj-3gj9-gm2p"}],"affected":[{"package":{"name":"qs","ecosystem":"npm","purl":"pkg:npm/qs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.0.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-crvj-3gj9-gm2p/GHSA-crvj-3gj9-gm2p.json"}}],"schema_version":"1.9.0"}