Show plain JSON{"affected_release": [{"advisory": "RHSA-2018:1263", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "fh-system-dump-tool-0:1.0.0-5.el7", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1263", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "fping-0:3.10-4.el7map", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1263", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "nagios-0:4.0.8-8.el7map", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1263", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "nagios-plugins-0:2.0.3-3.el7map", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1263", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "perl-Crypt-CBC-0:2.33-2.el7map", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1263", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "perl-Crypt-DES-0:2.05-20.el7map", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1263", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "perl-Net-SNMP-0:6.0.1-7.el7map", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1263", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "phantomjs-0:1.9.7-3.el7map", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1263", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "python-meld3-0:0.6.10-1.el7map", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1263", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "qstat-0:2.11-13.20080912svn311.el7map", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1263", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "radiusclient-ng-0:0.5.6-9.el7map", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1263", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "redis-0:2.8.21-2.el7map", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1263", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "rhmap-fh-openshift-templates-0:4.6.0-5.el7", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1263", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "rhmap-mod_authnz_external-0:3.3.1-7.el7map", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1263", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "sendEmail-0:1.56-2.el7", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1263", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "ssmtp-0:2.64-14.el7map", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1263", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "supervisor-0:3.1.3-3.el7map", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1264", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "rhmap46/fh-aaa:1.1.3-4", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1264", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "rhmap46/fh-appstore:2.1.2-3", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1264", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "rhmap46/fh-mbaas:6.0.3-2", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1264", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "rhmap46/fh-messaging:3.2.0-4", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1264", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "rhmap46/fh-metrics:3.2.0-5", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1264", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "rhmap46/fh-ngui:5.19.3-1", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1264", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "rhmap46/fh-scm:1.1.4-2", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1264", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "rhmap46/fh-sdks:1.0.0-36", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1264", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "rhmap46/fh-statsd:2.1.3-4", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1264", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "rhmap46/fh-supercore:5.0.10-2", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1264", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "rhmap46/gitlab-shell:2.1.2-16", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1264", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "rhmap46/httpd:2.4-47", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1264", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "rhmap46/installer:1.0.0-42", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1264", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "rhmap46/memcached:1.4.15-32", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1264", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "rhmap46/millicore:7.55.0-4", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1264", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "rhmap46/mongodb:3.2-36", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1264", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "rhmap46/mysql:5.5-28", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1264", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "rhmap46/nagios:4.0.8-58", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1264", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "rhmap46/redis:2.8.21-40", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1264", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "rhmap46/ups-eap:1.1.4-35", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2018:1264", "cpe": "cpe:/a:redhat:mobile_application_platform:4.6", "package": "rhmap46/wildcard-proxy:1.0.0-17", "product_name": "Red Hat Mobile Application Platform 4.6", "release_date": "2018-04-30T00:00:00Z"}, {"advisory": "RHSA-2017:2912", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "rh-nodejs4-nodejs-tough-cookie-0:2.3.3-2.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6", "release_date": "2017-10-18T00:00:00Z"}, {"advisory": "RHSA-2017:2913", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "rh-nodejs6-nodejs-tough-cookie-0:2.3.3-1.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6", "release_date": "2017-10-18T00:00:00Z"}, {"advisory": "RHSA-2017:2912", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "rh-nodejs4-nodejs-tough-cookie-0:2.3.3-2.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS", "release_date": "2017-10-18T00:00:00Z"}, {"advisory": "RHSA-2017:2913", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "rh-nodejs6-nodejs-tough-cookie-0:2.3.3-1.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS", "release_date": "2017-10-18T00:00:00Z"}, {"advisory": "RHSA-2017:2912", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el7", "package": "rh-nodejs4-nodejs-tough-cookie-0:2.3.3-2.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7", "release_date": "2017-10-18T00:00:00Z"}, {"advisory": "RHSA-2017:2913", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el7", "package": "rh-nodejs6-nodejs-tough-cookie-0:2.3.3-1.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7", "release_date": "2017-10-18T00:00:00Z"}, {"advisory": "RHSA-2017:2912", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el7", "package": "rh-nodejs4-nodejs-tough-cookie-0:2.3.3-2.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS", "release_date": "2017-10-18T00:00:00Z"}, {"advisory": "RHSA-2017:2913", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el7", "package": "rh-nodejs6-nodejs-tough-cookie-0:2.3.3-1.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS", "release_date": "2017-10-18T00:00:00Z"}], "bugzilla": {"description": "nodejs-tough-cookie: Regular expression denial of service", "id": "1493989", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1493989"}, "csaw": false, "cvss3": {"cvss3_base_score": "5.3", "cvss3_scoring_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "status": "verified"}, "cwe": "CWE-400", "details": ["A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module before 2.3.3 for Node.js. An attacker that is able to make an HTTP request using a specially crafted cookie may cause the application to consume an excessive amount of CPU.", "A regular expression denial of service flaw was found in Tough-Cookie. An attacker able to make an application using Touch-Cookie to parse a sufficiently large HTTP request Cookie header could cause the application to consume an excessive amount of CPU."], "name": "CVE-2017-15010", "package_state": [{"cpe": "cpe:/a:redhat:openshift:3", "fix_state": "Not affected", "package_name": "nodejs-tough-cookie", "product_name": "Red Hat OpenShift Enterprise 3"}, {"cpe": "cpe:/a:redhat:quay:3", "fix_state": "Not affected", "package_name": "quay/quay-rhel8", "product_name": "Red Hat Quay 3"}], "public_date": "2017-09-05T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2017-15010\nhttps://nvd.nist.gov/vuln/detail/CVE-2017-15010\nhttps://nodesecurity.io/advisories/525"], "statement": "Red Hat Quay include nodejs-tough-cookie as a build time dependency of protractor. It's no included in the runtime code, and is therefore not affected by this vulnerability.", "threat_severity": "Moderate"}