Debian Node-Tough-Cookie vulnerabilities
2 known vulnerabilities affecting debian/node-tough-cookie.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2023-26136P3MEDIUMCVSS 6.5fixed in node-tough-cookie 4.0.0-2+deb12u1 (bookworm)2023
CVE-2023-26136 [MEDIUM] CVE-2023-26136: node-tough-cookie - Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Po...
Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are initialized.
Scope: local
bookworm: resolved (fixed in 4.0.0-2+deb12u1)
bullseye: resolved (fixed in 4.0.0-2+deb11u1
debian
CVE-2017-15010P3HIGHCVSS 7.5fixed in node-tough-cookie 2.3.4+dfsg-1 (bookworm)2017
CVE-2017-15010 [HIGH] CVE-2017-15010: node-tough-cookie - A ReDoS (regular expression denial of service) flaw was found in the tough-cooki...
A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module before 2.3.3 for Node.js. An attacker that is able to make an HTTP request using a specially crafted cookie may cause the application to consume an excessive amount of CPU.
Scope: local
bookworm: resolved (fixed in 2.3.4+dfsg-1)
bullseye: resolved (fixed in 2.3.4+dfsg-
debian