Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: deprecate request-cookies available #5

Open
matmar10 opened this issue Nov 18, 2021 · 0 comments
Open

chore: deprecate request-cookies available #5

matmar10 opened this issue Nov 18, 2021 · 0 comments

Comments

@matmar10
Copy link
Collaborator

matmar10 commented Nov 18, 2021

Only used in one line, and module is 8 years old with no fix available for high severity issue:

tough-cookie  <=2.3.2
Severity: high
Regular Expression Denial of Service in tough-cookie - https://github.com/advisories/GHSA-g7q5-pjjr-gqvp
ReDoS via long string of semicolons in tough-cookie - https://github.com/advisories/GHSA-qhv9-728r-6jqg
No fix available
node_modules/request-cookies/node_modules/tough-cookie
  request-cookies  *
  Depends on vulnerable versions of tough-cookie
  node_modules/request-cookies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant