445
VMScore

CVE-2016-1000232

Published: 05/09/2018 Updated: 31/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial of Service. This attack appear to be exploitable via Custom HTTP header passed by client. This vulnerability appears to have been fixed in 2.3.0.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

salesforce tough-cookie

ibm api connect

ibm api connect 5.0.8.0

redhat openshift container platform 3.3

redhat openshift container platform 3.1

redhat openshift container platform 3.2

Vendor Advisories

Synopsis Moderate: rh-nodejs4-nodejs-tough-cookie security update Type/Severity Security Advisory: Moderate Topic An update for rh-nodejs4-nodejs-tough-cookie is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vu ...
Synopsis Moderate: nodejs and nodejs-tough-cookie security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for nodejs-tough-cookie and nodejs is now available for Red Hat OpenShift Container Platform 31, 32, and 33Red Hat Product Security has rated this update ...