Vulnerabilities/

tough-cookie Prototype Pollution vulnerability

Severity:
Medium

Description

Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are initialized.

Recommendation

Update the tough-cookie package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
tough-cookie
Anything's wrong? Let us know Last updated on June 21, 2024

This issue is available in SmartScanner Professional

See Pricing