Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security vulnerability in tough-cookie through request #90

Closed
holm opened this issue Jul 25, 2016 · 1 comment
Closed

Security vulnerability in tough-cookie through request #90

holm opened this issue Jul 25, 2016 · 1 comment
Assignees
Labels
🚨 This issue needs some love. triage me I really want to be triaged.

Comments

@holm
Copy link

holm commented Jul 25, 2016

tough-cookie has a ReDOS vulnerability that is fixed in 2.3.0. This repo depends on request, which has recently been updated to require the fixed version. See https://nodesecurity.io/advisories/130.

It would be great if this could be updated to support 2.74.0 of request and released.

@tbetbetbe
Copy link
Contributor

ok, will do shortly

On 25 July 2016 at 20:58, Christian Holm notifications@github.com wrote:

tough-cookie has a ReDOS vulnerability that is fixed in 2.3.0. This repo
depends on request, which has recently been updated to require the fixed
version. See https://nodesecurity.io/advisories/130.

It would be great if this could be updated to support 2.74.0 of request
and released.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub
#90, or mute
the thread
https://github.com/notifications/unsubscribe-auth/AI18FoRnMznZhc-YNOhIOd2wktiFalJjks5qZKUBgaJpZM4JUDKF
.

This email may be confidential or privileged. If you received this
communication by mistake, please don't forward it to anyone else (it may
contain confidential or privileged information), please erase all copies of
it, including all attachments, and please let the sender know it went to
the wrong person. Thanks.

@yoshi-automation yoshi-automation added 🚨 This issue needs some love. triage me I really want to be triaged. labels Apr 6, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
🚨 This issue needs some love. triage me I really want to be triaged.
Projects
None yet
Development

No branches or pull requests

3 participants