Junglewise Threat Intelligence

CVE-2016-1000232: tough-cookie ReDoS via semicolon strings

CVE-2016-1000232 · Severity: low · CVSS 3 · Published 2018-10-10

Technologies: tough-cookie (npm). Vendors: npm.

Executive brief

tough-cookie is a Node.js library that parses and manages HTTP cookies. A vulnerability in the cookie parsing logic allows attackers to trigger a regular expression denial of service (ReDoS) attack by sending Set-Cookie headers with long strings of semicolons, causing the application to consume excessive CPU and become unresponsive.

Technical details

The vulnerability is a regular expression denial of service (ReDoS) issue in the cookie parsing logic of tough-cookie. When processing Set-Cookie headers containing long strings of semicolons, the vulnerable regular expression exhibits catastrophic backtracking, causing exponential processing time. The attack is network-reachable and requires no authentication—any attacker can craft a malicious HTTP response with a crafted Set-Cookie header. The vulnerability affects all versions prior to 2.3.0. Exploitation results in denial of service through CPU exhaustion. The fix was implemented in version 2.3.0 and later.

Affected products

  • Salesforce tough-cookie before 2.3.0

Timeline

  • 2018-10-10: disclosed

References

Related threats