Salesforce tough-cookie 4.1.0 for Node.js

CPE Details

Salesforce tough-cookie 4.1.0 for Node.js
4.1.0
2023-07-07
14h39 +00:00
2023-07-13
12h54 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:salesforce:tough-cookie:4.1.0:*:*:*:*:node.js:*:*

Informations

Vendor

salesforce

Product

tough-cookie

Version

4.1.0

Target Software

node.js

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2023-26136 2023-07-01 05h00 +00:00 Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are initialized.
9.8
Critique