Skip to content

WS-2018-0588 (High severity) detected in querystringify #2000

@eKristensen

Description

@eKristensen
  • Operating System: Windows 10
  • Node Version: 10.15.3
  • NPM Version: 6.4.1
  • webpack Version: 4.33.0
  • webpack-dev-server Version: 3.7.1
  • This is a bug
  • This is a modification request

Code

No code, see unshiftio/querystringify#19

Expected Behavior

To be secure

Actual Behavior

A vulnerability was found in querystringify before 2.0.0.

For Bugs; How can we reproduce the behavior?

A vulnerability was found in querystringify before 2.0.0. It's possible to override built-in properties of the resulting query string object if a malicious string is inserted in the query string.

For Features; What is the motivation and/or use-case for the feature?

Security. See more here: unshiftio/querystringify#19

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions