CVE-2024-57067

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Feb 5, 2025
Updated: Feb 6, 2025
CWE ID 1321

Summary

CVE-2024-57067 is a prototype pollution vulnerability affecting the lib.parse function in version 0.2.0 of the popular query string parser library, dot-qs. This issue enables attackers to cause a Denial of Service (DoS) by supplying crafted payloads to the library. By manipulating the input data in a specific way, attackers can exploit the vulnerability to inject malicious data into the library's prototypes, leading to an unintended behavior and ultimately crashing the application. The impact of this issue can range from a simple application crash to more complex attacks, making it essential for affected organizations to apply the necessary patches as soon as possible to mitigate the risks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share