VulnerabilityModified
CVE-2016-1000232
NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial of Service.
MEDIUM 5.3EPSS 2.36%
Does this matter?
Lower severity and a low EPSS score (2.36%). Track it; it rarely justifies an emergency change on its own.
Description
NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial of Service. This attack appear to be exploitable via Custom HTTP header passed by client. This vulnerability appears to have been fixed in 2.3.0.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS
- 2.36% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- salesforce/tough-cookie · ibm/api connect · redhat/openshift container platform
- Source
- cve@mitre.org
References
- https://access.redhat.com/errata/RHSA-2016:2101Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2912Third Party Advisory
- https://access.redhat.com/security/cve/cve-2016-1000232Third Party Advisory
- https://github.com/salesforce/tough-cookie/commit/615627206357d997d5e6ff9da158997de05235aePatch, Third Party Advisory
- https://github.com/salesforce/tough-cookie/commit/e4fc2e0f9ee1b7a818d68f0ac7ea696f377b1534Patch, Third Party Advisory
- https://www.ibm.com/blogs/psirt/ibm-security-bulletin-ibm-api-connect-is-affected-by-node-js-tough-cookie-module-vulnerability-to-a-denial-of-service-cve-2016-1000232/Third Party Advisory
- https://www.npmjs.com/advisories/130Third Party Advisory
- https://access.redhat.com/errata/RHSA-2016:2101Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2912Third Party Advisory
- https://access.redhat.com/security/cve/cve-2016-1000232Third Party Advisory
- https://github.com/salesforce/tough-cookie/commit/615627206357d997d5e6ff9da158997de05235aePatch, Third Party Advisory
- https://github.com/salesforce/tough-cookie/commit/e4fc2e0f9ee1b7a818d68f0ac7ea696f377b1534Patch, Third Party Advisory
- https://www.ibm.com/blogs/psirt/ibm-security-bulletin-ibm-api-connect-is-affected-by-node-js-tough-cookie-module-vulnerability-to-a-denial-of-service-cve-2016-1000232/Third Party Advisory
- https://www.npmjs.com/advisories/130Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.