Debian 12 — node-cookiejar — vulnerability — patch and remediation guide
🟢 Low ⏱ 5–15 min Last verified: 6 August 2024 Affected versions: Debian 12 (bookworm) 📖 ~4 min read • Source: Debian Security Tracker Related CVEs: CVE-2022-25901 Upstream summary: Versions of the package cookiejar before 2.1.4 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Cookie.parse function, which uses an insecure regular […]