PT-2017-13815 · Node.Js · Tough-Cookie

Publicado

2017-10-03

·

Atualizado

2019-06-12

·

CVE-2017-15010

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions tough-cookie versions prior to 2.3.3
Description A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module for Node.js. An attacker can make an HTTP request using a specially crafted cookie to cause the application to consume an excessive amount of CPU. The amplification of this issue is relatively low, taking around 2 seconds to execute on a malicious input of 50,000 characters. However, if Node.js was compiled with the -DHTTP MAX HEADER SIZE flag, the impact can be significant due to the default max HTTP header length limitation in Node.js.
Recommendations Update to version 2.3.3 or later.

Correção

DoS

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-15010
GHSA-G7Q5-PJJR-GQVP
RHSA-2017:2912
RHSA-2017:2913
RHSA-2018:1263

Produtos afetados

Tough-Cookie