Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h. On successful exploitation this vulnerability allows attackers to remotely execute arbitrary code in the context of the vulnerable service.
Loading...
Loading...
Score 9.8 from GitHub Security Advisory (severity: CRITICAL) published 2022-08-05. NVD baseline CVSS 9.8; sources differ by 0.0.
Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h. On successful exploitation this vulnerability allows attackers to remotely execute arbitrary code in the context of the vulnerable service.
August 4, 2022
November 21, 2024
Patch available: CrowCpp/Crow v1.0+4
https://github.com/CrowCpp/Crow/releases/tag/v1.0%2B4Patch available: CrowCpp/Crow v1.1.0 (PR #486 merged 2022-06-28)
https://github.com/CrowCpp/Crow/pull/486MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
See which npm, PyPI, Go, and Maven packages are affected by CVE-2022-34970
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.