MEDIUM5.3
GHSA-qhv9-728r-6jqg
ReDoS via long string of semicolons in tough-cookie
Quick fix
GHSA-qhv9-728r-6jqg — tough-cookie: upgrade to the fixed version with the command below.
npm install tough-cookie@2.3.0Details
Affected versions of `tough-cookie` may be vulnerable to regular expression denial of service when long strings of semicolons exist in the `Set-Cookie` header.
## Recommendation
Update to version 2.3.0 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2016-1000232[ADVISORY]
- https://github.com/salesforce/tough-cookie/commit/615627206357d997d5e6ff9da158997de05235ae[WEB]
- https://github.com/salesforce/tough-cookie/commit/e4fc2e0f9ee1b7a818d68f0ac7ea696f377b1534[WEB]
- https://access.redhat.com/errata/RHSA-2016:2101[WEB]
- https://access.redhat.com/errata/RHSA-2017:2912[WEB]
- https://access.redhat.com/security/cve/cve-2016-1000232[WEB]
- https://github.com/advisories/GHSA-qhv9-728r-6jqg[ADVISORY]
- https://github.com/salesforce/tough-cookie[PACKAGE]
- https://www.ibm.com/blogs/psirt/ibm-security-bulletin-ibm-api-connect-is-affected-by-node-js-tough-cookie-module-vulnerability-to-a-denial-of-service-cve-2016-1000232[WEB]
- https://www.npmjs.com/advisories/130[WEB]