PT-2017-13815 · Node.Js · Tough-Cookie
Publicado
2017-10-03
·
Atualizado
2019-06-12
·
CVE-2017-15010
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
tough-cookie versions prior to 2.3.3
Description
A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module for Node.js. An attacker can make an HTTP request using a specially crafted cookie to cause the application to consume an excessive amount of CPU. The amplification of this issue is relatively low, taking around 2 seconds to execute on a malicious input of 50,000 characters. However, if Node.js was compiled with the
-DHTTP MAX HEADER SIZE flag, the impact can be significant due to the default max HTTP header length limitation in Node.js.Recommendations
Update to version 2.3.3 or later.
Correção
DoS
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Tough-Cookie