{
  "threat_severity" : "Moderate",
  "public_date" : "2017-09-05T00:00:00Z",
  "bugzilla" : {
    "description" : "nodejs-tough-cookie: Regular expression denial of service",
    "id" : "1493989",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1493989"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.3",
    "cvss3_scoring_vector" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
    "status" : "verified"
  },
  "cwe" : "CWE-400",
  "details" : [ "A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module before 2.3.3 for Node.js. An attacker that is able to make an HTTP request using a specially crafted cookie may cause the application to consume an excessive amount of CPU.", "A regular expression denial of service flaw was found in Tough-Cookie. An attacker able to make an application using Touch-Cookie to parse a sufficiently large HTTP request Cookie header could cause the application to consume an excessive amount of CPU." ],
  "statement" : "Red Hat Quay include nodejs-tough-cookie as a build time dependency of protractor. It's no included in the runtime code, and is therefore not affected by this vulnerability.",
  "affected_release" : [ {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "fh-system-dump-tool-0:1.0.0-5.el7"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "fping-0:3.10-4.el7map"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "nagios-0:4.0.8-8.el7map"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "nagios-plugins-0:2.0.3-3.el7map"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "perl-Crypt-CBC-0:2.33-2.el7map"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "perl-Crypt-DES-0:2.05-20.el7map"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "perl-Net-SNMP-0:6.0.1-7.el7map"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "phantomjs-0:1.9.7-3.el7map"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "python-meld3-0:0.6.10-1.el7map"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "qstat-0:2.11-13.20080912svn311.el7map"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "radiusclient-ng-0:0.5.6-9.el7map"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "redis-0:2.8.21-2.el7map"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap-fh-openshift-templates-0:4.6.0-5.el7"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap-mod_authnz_external-0:3.3.1-7.el7map"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "sendEmail-0:1.56-2.el7"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "ssmtp-0:2.64-14.el7map"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "supervisor-0:3.1.3-3.el7map"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/fh-aaa:1.1.3-4"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/fh-appstore:2.1.2-3"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/fh-mbaas:6.0.3-2"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/fh-messaging:3.2.0-4"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/fh-metrics:3.2.0-5"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/fh-ngui:5.19.3-1"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/fh-scm:1.1.4-2"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/fh-sdks:1.0.0-36"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/fh-statsd:2.1.3-4"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/fh-supercore:5.0.10-2"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/gitlab-shell:2.1.2-16"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/httpd:2.4-47"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/installer:1.0.0-42"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/memcached:1.4.15-32"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/millicore:7.55.0-4"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/mongodb:3.2-36"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/mysql:5.5-28"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/nagios:4.0.8-58"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/redis:2.8.21-40"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/ups-eap:1.1.4-35"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/wildcard-proxy:1.0.0-17"
  }, {
    "product_name" : "Red Hat Software Collections for Red Hat Enterprise Linux 6",
    "release_date" : "2017-10-18T00:00:00Z",
    "advisory" : "RHSA-2017:2912",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:2::el6",
    "package" : "rh-nodejs4-nodejs-tough-cookie-0:2.3.3-2.el6"
  }, {
    "product_name" : "Red Hat Software Collections for Red Hat Enterprise Linux 6",
    "release_date" : "2017-10-18T00:00:00Z",
    "advisory" : "RHSA-2017:2913",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:2::el6",
    "package" : "rh-nodejs6-nodejs-tough-cookie-0:2.3.3-1.el6"
  }, {
    "product_name" : "Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS",
    "release_date" : "2017-10-18T00:00:00Z",
    "advisory" : "RHSA-2017:2912",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:2::el6",
    "package" : "rh-nodejs4-nodejs-tough-cookie-0:2.3.3-2.el6"
  }, {
    "product_name" : "Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS",
    "release_date" : "2017-10-18T00:00:00Z",
    "advisory" : "RHSA-2017:2913",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:2::el6",
    "package" : "rh-nodejs6-nodejs-tough-cookie-0:2.3.3-1.el6"
  }, {
    "product_name" : "Red Hat Software Collections for Red Hat Enterprise Linux 7",
    "release_date" : "2017-10-18T00:00:00Z",
    "advisory" : "RHSA-2017:2912",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:2::el7",
    "package" : "rh-nodejs4-nodejs-tough-cookie-0:2.3.3-2.el7"
  }, {
    "product_name" : "Red Hat Software Collections for Red Hat Enterprise Linux 7",
    "release_date" : "2017-10-18T00:00:00Z",
    "advisory" : "RHSA-2017:2913",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:2::el7",
    "package" : "rh-nodejs6-nodejs-tough-cookie-0:2.3.3-1.el7"
  }, {
    "product_name" : "Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS",
    "release_date" : "2017-10-18T00:00:00Z",
    "advisory" : "RHSA-2017:2912",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:2::el7",
    "package" : "rh-nodejs4-nodejs-tough-cookie-0:2.3.3-2.el7"
  }, {
    "product_name" : "Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS",
    "release_date" : "2017-10-18T00:00:00Z",
    "advisory" : "RHSA-2017:2913",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:2::el7",
    "package" : "rh-nodejs6-nodejs-tough-cookie-0:2.3.3-1.el7"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat OpenShift Enterprise 3",
    "fix_state" : "Not affected",
    "package_name" : "nodejs-tough-cookie",
    "cpe" : "cpe:/a:redhat:openshift:3"
  }, {
    "product_name" : "Red Hat Quay 3",
    "fix_state" : "Not affected",
    "package_name" : "quay/quay-rhel8",
    "cpe" : "cpe:/a:redhat:quay:3"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2017-15010\nhttps://nvd.nist.gov/vuln/detail/CVE-2017-15010\nhttps://nodesecurity.io/advisories/525" ],
  "name" : "CVE-2017-15010",
  "csaw" : false
}