Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2021-44907: Edit fiddle - JSFiddle - Code Playground

A Denial of Service vulnerability exists in qs up to 6.8.0 due to insufficient sanitization of property in the gs.parse function. The merge() function allows the assignment of properties on an array in the query. For any property being assigned, a value in the array is converted to an object containing these properties. Essentially, this means that the property whose expected type is Array always has to be checked with Array.isArray() by the user. This may not be obvious to the user and can cause unexpected behavior.

CVE
#vulnerability#dos#js#git#java

Run

Save

Fork

Set as base

Collaborate

  • Settings
  • Sign in

Editor layout

Classic Columns Bottom results Right results Tabs (columns) Tabs (rows)

Console

Console in the editor (beta)

Clear console on run

General

Line numbers

Wrap lines

Indent with tabs

Code hinting (autocomplete) (beta)

Behavior

Auto-run code

Only auto-run code that validates

Auto-save code (bumps the version)

Auto-close HTML tags

Auto-close brackets

Live code validation

Highlight matching tags

Boilerplates

Show boilerplates bar less often

Save anonymous (public) fiddle?

- Be sure not to include personal data
- Do not include copyrighted material

Log in if you’d like to delete this fiddle in the future.

Fork anonymous (public) fiddle?

- Be sure not to include personal data
- Do not include copyrighted material

Log in if you’d like to delete this fiddle in the future.

Tabs:

JavaScript HTML CSS Result

Visual:

Light Dark

Embed snippet Prefer iframe?:

No autoresizing to fit the code

Render blocking of the parent page

Fiddle meta

Resources URL cdnjs 0

  • Paste a direct CSS/JS URL
  • Type a library name to fetch from CDNJS

Async requests

/echo simulates Async calls:
JSON: /echo/json/
JSONP: //jsfiddle.net/echo/jsonp/
HTML: /echo/html/
XML: /echo/xml/

See docs for more info.

Other (links, license)

Created and maintained by Piotr and Oskar.

Hosted on DigitalOcean

All code belongs to the poster and no license is enforced. JSFiddle or its authors are not responsible or liable for any loss or damage of any kind during the usage of provided code.

Links

Bug tracker
Roadmap (vote for features)
About
Docs
Service status

Language****Doctype****Body tag

Language****Frameworks & Extensions****Framework <script> attribute

Language****Options

Normalized CSS

  • This fiddle has previously unsaved changes. Apply changes Discard

IE is no longer supported 📠

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907