PT-2017-13815 · Node.Js · Tough-Cookie

Published

2017-10-03

·

Updated

2019-06-12

·

CVE-2017-15010

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions tough-cookie versions prior to 2.3.3
Description A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module for Node.js. An attacker can make an HTTP request using a specially crafted cookie to cause the application to consume an excessive amount of CPU. The amplification of this issue is relatively low, taking around 2 seconds to execute on a malicious input of 50,000 characters. However, if Node.js was compiled with the -DHTTP MAX HEADER SIZE flag, the impact can be significant due to the default max HTTP header length limitation in Node.js.
Recommendations Update to version 2.3.3 or later.

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-15010
GHSA-G7Q5-PJJR-GQVP
RHSA-2017:2912
RHSA-2017:2913
RHSA-2018:1263

Affected Products

Tough-Cookie