7.5
CVSSv3

CVE-2017-15010

Published: 04/10/2017 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module prior to 2.3.3 for Node.js. An attacker that is able to make an HTTP request using a specially crafted cookie may cause the application to consume an excessive amount of CPU.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

salesforce tough-cookie

Vendor Advisories

Debian Bug report logs - #877660 CVE-2017-15010 Package: node-tough-cookie; Maintainer for node-tough-cookie is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Source for node-tough-cookie is src:node-tough-cookie (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Dat ...
Synopsis Moderate: rh-nodejs6-nodejs-tough-cookie security update Type/Severity Security Advisory: Moderate Topic An update for rh-nodejs6-nodejs-tough-cookie is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vu ...
Synopsis Moderate: rh-nodejs4-nodejs-tough-cookie security update Type/Severity Security Advisory: Moderate Topic An update for rh-nodejs4-nodejs-tough-cookie is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vu ...
Synopsis Moderate: Red Hat Mobile Application Platform 460 release - RPMs Type/Severity Security Advisory: Moderate Topic Red Hat Mobile Application Platform 460 release - RPMs Description Red Hat Mobile Application Platform (RHMAP) 46 is delivered as a set of container imagesIn addit ...
Synopsis Moderate: Red Hat Mobile Application Platform 460 Release - Container Images Type/Severity Security Advisory: Moderate Topic Red Hat Mobile Application Platform 460 Release - Container Images Description Red Hat Mobile Application Platform (RHMAP) 460 consists of three main c ...
A regular expression denial of service flaw was found in Tough-Cookie An attacker able to make an application using Touch-Cookie to parse a sufficiently large HTTP request Cookie header could cause the application to consume an excessive amount of CPU ...