Versions of the package cookiejar before 2.1.4 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Cookie.parse function, which uses an insecure regular expression.
References
Configurations
History
13 Feb 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) Versions of the package cookiejar before 2.1.4 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Cookie.parse function, which uses an insecure regular expression. |
Information
Published : 2023-01-18 05:15
Updated : 2025-02-13 17:15
NVD link : CVE-2022-25901
Mitre link : CVE-2022-25901
CVE.ORG link : CVE-2022-25901
JSON object : View
Products Affected
cookiejar_project
- cookiejar
CWE
CWE-1333
Inefficient Regular Expression Complexity