CVE-2016-1000232
Last modified
CVE-2016-1000232 is a vulnerability of currently unknown severity. NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial of Service. This attack appear to be exploitable via Custom HTTP header passed by client. EPSS estimates a 2.36% chance of exploitation in the next 30 days.
Description
NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial of Service. This attack appear to be exploitable via Custom HTTP header passed by client. This vulnerability appears to have been fixed in 2.3.0.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Salesforce | Tough-Cookie | >= 0.9.7, <= 2.2.2 |
| Ibm | Api Connect | >= 5.0.6.0, <= 5.0.6.5 |
| Ibm | Api Connect | >= 5.0.7.0, <= 5.0.7.2 |
| Ibm | Api Connect | 5.0.8.0 |
| Redhat | Openshift Container Platform | 3.1 |
| Redhat | Openshift Container Platform | 3.2 |
| Redhat | Openshift Container Platform | 3.3 |
References
- https://access.redhat.com/errata/RHSA-2016:2101Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2912Third Party Advisory
- https://access.redhat.com/security/cve/cve-2016-1000232Third Party Advisory
- https://github.com/salesforce/tough-cookie/commit/615627206357d997d5e6ff9da158997de05235aePatch, Third Party Advisory
- https://github.com/salesforce/tough-cookie/commit/e4fc2e0f9ee1b7a818d68f0ac7ea696f377b1534Patch, Third Party Advisory
- https://www.npmjs.com/advisories/130Third Party Advisory
- https://access.redhat.com/errata/RHSA-2016:2101Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2912Third Party Advisory
- https://access.redhat.com/security/cve/cve-2016-1000232Third Party Advisory
- https://github.com/salesforce/tough-cookie/commit/615627206357d997d5e6ff9da158997de05235aePatch, Third Party Advisory
- https://github.com/salesforce/tough-cookie/commit/e4fc2e0f9ee1b7a818d68f0ac7ea696f377b1534Patch, Third Party Advisory
- https://www.npmjs.com/advisories/130Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-1000232?
How severe is CVE-2016-1000232?
How do I fix CVE-2016-1000232?
Are you affected by CVE-2016-1000232?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
