Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-25901
HistoryJan 18, 2023 - 5:15 a.m.

Design/Logic Flaw

2023-01-1805:15:00
PRIOn knowledge base
www.prio-n.com
5
redos
cookiejar
insecure regex

7.4 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

67.9%

Versions of the package cookiejar before 2.1.4 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Cookie.parse function, which uses an insecure regular expression.

CPENameOperatorVersion
cookiejarle2.1.3

7.4 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

67.9%