Salesforce tough-cookie 0.9.6 for Node.js

CPE Details

Salesforce tough-cookie 0.9.6 for Node.js
0.9.6
2019-06-20
14h25 +00:00
2019-06-20
14h25 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:salesforce:tough-cookie:0.9.6:*:*:*:*:node.js:*:*

Informations

Vendor

salesforce

Product

tough-cookie

Version

0.9.6

Target Software

node.js

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-26136 2023-07-01 05h00 +00:00 Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are initialized.
9.8
Critical
CVE-2017-15010 2017-10-03 14h00 +00:00 A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module before 2.3.3 for Node.js. An attacker that is able to make an HTTP request using a specially crafted cookie may cause the application to consume an excessive amount of CPU.
7.5
High