CVE-2022-25901: High severity Cookiejar Project Cookiejar Node.js vulnerability
Versions of the package cookiejar before 2.1.4 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Cookie.parse function, which uses an insecure regular expression.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
cookiejarto a version that resolves this vulnerability.Fixed in 2.1.4
Event History
Frequently Asked Questions
What is CVE-2022-25901?
CVE-2022-25901 is a vulnerability in the cookiejar package before version 2.1.4 that allows for Regular Expression Denial of Service (ReDoS) attacks.
How does CVE-2022-25901 impact me?
If you are using the cookiejar package before version 2.1.4, an attacker could launch a ReDoS attack, potentially causing a denial of service on your system.
How to fix CVE-2022-25901?
To fix CVE-2022-25901, you should update the cookiejar package to version 2.1.4 or later.
Are there any references for CVE-2022-25901?
Yes, you can find references for CVE-2022-25901 at the following links: [Link 1](https://github.com/bmeck/node-cookiejar/blob/master/cookiejar.js#L73), [Link 2](https://github.com/bmeck/node-cookiejar/pull/39), [Link 3 - Commit](https://github.com/bmeck/node-cookiejar/pull/39/commits/eaa00021caf6ae09449dde826108153b578348e5).
What is the Common Weakness Enumeration (CWE) related to CVE-2022-25901?
The Common Weakness Enumeration (CWE) related to CVE-2022-25901 is CWE-1333, which is for Regular Expression Denial of Service (ReDoS).