CVE-2016-1000232
Last modified
CVE-2016-1000232 is a vulnerability of currently unknown severity. NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial of Service. This attack appear to be exploitable via Custom HTTP header passed by client. EPSS estimates a 2.36% chance of exploitation in the next 30 days.
Description
NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial of Service. This attack appear to be exploitable via Custom HTTP header passed by client. This vulnerability appears to have been fixed in 2.3.0.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Salesforce | Tough-Cookie | >= 0.9.7, <= 2.2.2 |
| Ibm | Api Connect | >= 5.0.6.0, <= 5.0.6.5 |
| Ibm | Api Connect | >= 5.0.7.0, <= 5.0.7.2 |
| Ibm | Api Connect | 5.0.8.0 |
| Redhat | Openshift Container Platform | 3.1 |
| Redhat | Openshift Container Platform | 3.2 |
| Redhat | Openshift Container Platform | 3.3 |
References
- https://access.redhat.com/errata/RHSA-2016:2101Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2912Third Party Advisory
- https://access.redhat.com/security/cve/cve-2016-1000232Third Party Advisory
- https://github.com/salesforce/tough-cookie/commit/615627206357d997d5e6ff9da158997de05235aePatch, Third Party Advisory
- https://github.com/salesforce/tough-cookie/commit/e4fc2e0f9ee1b7a818d68f0ac7ea696f377b1534Patch, Third Party Advisory
- https://www.npmjs.com/advisories/130Third Party Advisory
- https://access.redhat.com/errata/RHSA-2016:2101Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2912Third Party Advisory
- https://access.redhat.com/security/cve/cve-2016-1000232Third Party Advisory
- https://github.com/salesforce/tough-cookie/commit/615627206357d997d5e6ff9da158997de05235aePatch, Third Party Advisory
- https://github.com/salesforce/tough-cookie/commit/e4fc2e0f9ee1b7a818d68f0ac7ea696f377b1534Patch, Third Party Advisory
- https://www.npmjs.com/advisories/130Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-1000232?
How severe is CVE-2016-1000232?
How do I fix CVE-2016-1000232?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-1000218Kibana Reporting plugin version 2.4.0 is vulnerable to a CSR…
- CVE-2016-1000219Kibana before 4.5.4 and 4.1.11 when a custom output is confi…
- CVE-2016-1000220Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS atta…
- CVE-2016-1000221Logstash prior to version 2.3.4, Elasticsearch Output plugin…
- CVE-2016-1000222Logstash prior to version 2.1.2, the CSV output can be attac…
- CVE-2016-1000229swagger-ui has XSS in key names6.1
- CVE-2016-1000236Node-cookie-signature before 1.0.6 is affected by a timing a…4.4
- CVE-2016-1000237sanitize-html before 1.4.3 has XSS.6.1
- CVE-2016-1000258Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2016-1000259Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2016-1000268Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2016-1000271Joomla extension DT Register version before 3.1.12 (Joomla 3…
Are you affected by CVE-2016-1000232?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
