Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are initialized.
References
Configurations
History
No history.
Information
Published : 2023-07-01 05:15
Updated : 2024-06-21 19:15
NVD link : CVE-2023-26136
Mitre link : CVE-2023-26136
CVE.ORG link : CVE-2023-26136
JSON object : View
Products Affected
salesforce
- tough-cookie
CWE
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')