QID 982194
QID 982194: Nodejs (npm) Security Update for tough-cookie (GHSA-qhv9-728r-6jqg)
Affected versions of `tough-cookie` may be vulnerable to regular expression denial of service when long strings of semicolons exist in the `Set-Cookie` header.
## Recommendation
Update to version 2.3.0 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-qhv9-728r-6jqg for updates pertaining to this vulnerability.
Vendor References
- GHSA-qhv9-728r-6jqg -
github.com/advisories/GHSA-qhv9-728r-6jqg
CVEs related to QID 982194
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-qhv9-728r-6jqg | tough-cookie |
|