CVE-2023-26136: Critical severity Salesforce Tough-cookie Node.js vulnerability
Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are initialized.
Other sources
Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are initialized.
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-26136?
CVE-2023-26136 has a high severity rating due to the potential for remote code execution caused by the prototype pollution vulnerability.
How do I fix CVE-2023-26136?
To fix CVE-2023-26136, upgrade to the patched version of tough-cookie, specifically version 4.1.3 or later.
Which software products are affected by CVE-2023-26136?
CVE-2023-26136 affects Salesforce tough-cookie and IBM Cognos Analytics across several versions.
What attack vector is exploited in CVE-2023-26136?
CVE-2023-26136 can be exploited through the improper handling of Cookies in the rejectPublicSuffixes=false mode.
Can CVE-2023-26136 be exploited remotely?
Yes, CVE-2023-26136 can be exploited by remote attackers to execute arbitrary code on affected systems.