Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qhv9-728r-6jqg

Опубликовано: 10 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

ReDoS via long string of semicolons in tough-cookie

Affected versions of tough-cookie may be vulnerable to regular expression denial of service when long strings of semicolons exist in the Set-Cookie header.

Recommendation

Update to version 2.3.0 or later.

Пакеты

Наименование

tough-cookie

npm
Затронутые версииВерсия исправления

< 2.3.0

2.3.0

EPSS

Процентиль: 76%
0.00921
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-1333

Связанные уязвимости

CVSS3: 5.3
redhat
больше 9 лет назад

NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial of Service. This attack appear to be exploitable via Custom HTTP header passed by client. This vulnerability appears to have been fixed in 2.3.0.

CVSS3: 5.3
nvd
больше 7 лет назад

NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial of Service. This attack appear to be exploitable via Custom HTTP header passed by client. This vulnerability appears to have been fixed in 2.3.0.

EPSS

Процентиль: 76%
0.00921
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-1333