Описание
A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module before 2.3.3 for Node.js. An attacker that is able to make an HTTP request using a specially crafted cookie may cause the application to consume an excessive amount of CPU.
A regular expression denial of service flaw was found in Tough-Cookie. An attacker able to make an application using Touch-Cookie to parse a sufficiently large HTTP request Cookie header could cause the application to consume an excessive amount of CPU.
Отчет
Red Hat Quay include nodejs-tough-cookie as a build time dependency of protractor. It's no included in the runtime code, and is therefore not affected by this vulnerability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Enterprise 3 | nodejs-tough-cookie | Not affected | ||
| Red Hat Quay 3 | quay/quay-rhel8 | Not affected | ||
| Red Hat Mobile Application Platform 4.6 | fh-system-dump-tool | Fixed | RHSA-2018:1263 | 30.04.2018 |
| Red Hat Mobile Application Platform 4.6 | fping | Fixed | RHSA-2018:1263 | 30.04.2018 |
| Red Hat Mobile Application Platform 4.6 | nagios | Fixed | RHSA-2018:1263 | 30.04.2018 |
| Red Hat Mobile Application Platform 4.6 | nagios-plugins | Fixed | RHSA-2018:1263 | 30.04.2018 |
| Red Hat Mobile Application Platform 4.6 | perl-Crypt-CBC | Fixed | RHSA-2018:1263 | 30.04.2018 |
| Red Hat Mobile Application Platform 4.6 | perl-Crypt-DES | Fixed | RHSA-2018:1263 | 30.04.2018 |
| Red Hat Mobile Application Platform 4.6 | perl-Net-SNMP | Fixed | RHSA-2018:1263 | 30.04.2018 |
| Red Hat Mobile Application Platform 4.6 | phantomjs | Fixed | RHSA-2018:1263 | 30.04.2018 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module before 2.3.3 for Node.js. An attacker that is able to make an HTTP request using a specially crafted cookie may cause the application to consume an excessive amount of CPU.
A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module before 2.3.3 for Node.js. An attacker that is able to make an HTTP request using a specially crafted cookie may cause the application to consume an excessive amount of CPU.
A ReDoS (regular expression denial of service) flaw was found in the t ...
Regular Expression Denial of Service in tough-cookie
EPSS
5.3 Medium
CVSS3