Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2021-44907 #4865

Closed
wants to merge 1 commit into from
Closed

CVE-2021-44907 #4865

wants to merge 1 commit into from

Conversation

jmargieh
Copy link

@dougwilson
Copy link
Contributor

dougwilson commented Mar 20, 2022

A Denial of Service vulnerability exists in qs up to 6.8.0

Thank you for this 😀 this CVE says it applies to 6.8.0 of qs or lower. We have already upgraded past that and the CVE is addressed, no need to worry. The fixed qs version is available in Express 4.17.2 or later.

@dougwilson dougwilson closed this Mar 20, 2022
@expressjs expressjs locked as resolved and limited conversation to collaborators Apr 5, 2022
@jmargieh jmargieh deleted the patch-1 branch August 22, 2022 17:27
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants