VDB
RHSA-2018%3A1264
RHSA-2018%3A1264
PUBLISHED
CVSS 5.300000190734863 MEDIUM
A regular expression denial of service flaw was found in Tough-Cookie. An attacker able to make an application using Touch-Cookie to parse a sufficiently large HTTP request Cookie header could cause the application to consume an excessive amount of CPU.
Risk Scores
CVSS 3.0
5.300000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | rhmap46/memcached@sha256:65d5a737ae9380a7a041726a33c0b36e4065ec9ea6890d327034f03bb1ce0969_amd64 as a component of Red Hat Mobile Application Platform 4.6 | *, * |
| Red Hat | rhmap46/mongodb@sha256:bcfd94b74bfb049fc6c5649216d703f15fe22c2caf30121ade844760fdefc601_amd64 as a component of Red Hat Mobile Application Platform 4.6 | *, rhmap46/mongodb@sha256:bcfd94b74bfb049fc6c5649216d703f15fe22c2caf30121ade844760fdefc601_amd64 |
| Red Hat | rhmap46/millicore@sha256:babc8754be2c766a22461ce88b22fe18d17da84091e0dc4dd9e0edba8199e8f5_amd64 as a component of Red Hat Mobile Application Platform 4.6 | rhmap46/millicore@sha256:babc8754be2c766a22461ce88b22fe18d17da84091e0dc4dd9e0edba8199e8f5_amd64, * |
| Red Hat | rhmap46/wildcard-proxy@sha256:5abb752987bde3c20273f9b19266bd8ba2015a06336980f8cf02e3a1f969dbf8_amd64 as a component of Red Hat Mobile Application Platform 4.6 | *, rhmap46/wildcard-proxy@sha256:5abb752987bde3c20273f9b19266bd8ba2015a06336980f8cf02e3a1f969dbf8_amd64 |
| Red Hat | rhmap46/fh-supercore@sha256:5400eb2ef4cf354c94c47439e5d3ef4bd355a8951463f0ccb9db40e313cb509e_amd64 as a component of Red Hat Mobile Application Platform 4.6 | *, * |
| Red Hat | rhmap46/fh-ngui@sha256:b5dd33fabd680944f0075f6788ac3b5263a11a542ce51e6705dc0ad94aded656_amd64 as a component of Red Hat Mobile Application Platform 4.6 | *, rhmap46/fh-ngui@sha256:b5dd33fabd680944f0075f6788ac3b5263a11a542ce51e6705dc0ad94aded656_amd64 |
| Red Hat | rhmap46/fh-aaa@sha256:333fe3a6104328fdf7a163e6782bdc93083f5824a71c172e1a91d8cd2ac4dc45_amd64 as a component of Red Hat Mobile Application Platform 4.6 | rhmap46/fh-aaa@sha256:333fe3a6104328fdf7a163e6782bdc93083f5824a71c172e1a91d8cd2ac4dc45_amd64, * |
| Red Hat | Red Hat Mobile Application Platform 4.6 | |
| Red Hat | rhmap46/fh-sdks@sha256:91c35fb5b97a5487aac0db2e45d2aa9c22b8ae2fe96e564c333b89b8c1023683_amd64 as a component of Red Hat Mobile Application Platform 4.6 | *, * |
| Red Hat | rhmap46/nagios@sha256:321690d3b24c6281ee7b3bee9b7388676b96b5f3f2a6841bedc872614d73ecd8_amd64 as a component of Red Hat Mobile Application Platform 4.6 | *, rhmap46/nagios@sha256:321690d3b24c6281ee7b3bee9b7388676b96b5f3f2a6841bedc872614d73ecd8_amd64 |
| Red Hat | rhmap46/ups-eap@sha256:22ef1c2136573a99f278d5f1b384ee35244382a92a3ea2190e74d8ad660f009c_amd64 as a component of Red Hat Mobile Application Platform 4.6 | *, rhmap46/ups-eap@sha256:22ef1c2136573a99f278d5f1b384ee35244382a92a3ea2190e74d8ad660f009c_amd64 |
| Red Hat | rhmap46/httpd@sha256:338594491055c702411209edb55673d5718285fbf8e6d9241d8963ba929c3754_amd64 as a component of Red Hat Mobile Application Platform 4.6 | rhmap46/httpd@sha256:338594491055c702411209edb55673d5718285fbf8e6d9241d8963ba929c3754_amd64, * |
| Red Hat | rhmap46/fh-mbaas@sha256:978137bd62f018ed791f8f242e4f454aa5632260b74416a697af2788f6fa55bc_amd64 as a component of Red Hat Mobile Application Platform 4.6 | rhmap46/fh-mbaas@sha256:978137bd62f018ed791f8f242e4f454aa5632260b74416a697af2788f6fa55bc_amd64, * |
| Red Hat | rhmap46/installer@sha256:940137b25079909c06b724d838a48db58a98d49baf3cb9eee0e0a068deba44bb_amd64 as a component of Red Hat Mobile Application Platform 4.6 | rhmap46/installer@sha256:940137b25079909c06b724d838a48db58a98d49baf3cb9eee0e0a068deba44bb_amd64, * |
| Red Hat | rhmap46/mysql@sha256:e95585839f27c671609e0bafdb0c3e6752b114882b25b1b35d817142e738a597_amd64 as a component of Red Hat Mobile Application Platform 4.6 | rhmap46/mysql@sha256:e95585839f27c671609e0bafdb0c3e6752b114882b25b1b35d817142e738a597_amd64, * |
| Red Hat | rhmap46/fh-statsd@sha256:55122c42b06eb1202e471247b8f9e1a6af1f855ebd620af74d0c338665bba603_amd64 as a component of Red Hat Mobile Application Platform 4.6 | *, rhmap46/fh-statsd@sha256:55122c42b06eb1202e471247b8f9e1a6af1f855ebd620af74d0c338665bba603_amd64 |
| Red Hat | rhmap46/fh-metrics@sha256:4ae06c04142b0b146ca8a3da6da113d2600fd46307f501043c3a23040d89d2b0_amd64 as a component of Red Hat Mobile Application Platform 4.6 | *, rhmap46/fh-metrics@sha256:4ae06c04142b0b146ca8a3da6da113d2600fd46307f501043c3a23040d89d2b0_amd64 |
| Red Hat | rhmap46/redis@sha256:752ce940961048a174863aef559c8e303387f67bdbdbe1d91b197c9bbe7f773a_amd64 as a component of Red Hat Mobile Application Platform 4.6 | rhmap46/redis@sha256:752ce940961048a174863aef559c8e303387f67bdbdbe1d91b197c9bbe7f773a_amd64, * |
| Red Hat | rhmap46/fh-scm@sha256:5ce3e868c6c1a8a86c1bf29ddf0e08e82827d4a39eafd8c5f36229a83f4c880b_amd64 as a component of Red Hat Mobile Application Platform 4.6 | rhmap46/fh-scm@sha256:5ce3e868c6c1a8a86c1bf29ddf0e08e82827d4a39eafd8c5f36229a83f4c880b_amd64, * |
| Red Hat | rhmap46/gitlab-shell@sha256:e167f23019582aaca1791ba5f8c26825ea62d9885f6a06362f0a6648137381c7_amd64 as a component of Red Hat Mobile Application Platform 4.6 | *, rhmap46/gitlab-shell@sha256:e167f23019582aaca1791ba5f8c26825ea62d9885f6a06362f0a6648137381c7_amd64 |
…and 2 more
Timeline
- Apr 30, 2018 CVE Published
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- May 13, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2018:1264 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1493989 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1545893 issue
- https://issues.redhat.com/browse/RHMAP-19902 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2018/rhsa-2018_1264.json advisory
- https://access.redhat.com/security/cve/CVE-2017-15010 advisory
- https://www.cve.org/CVERecord?id=CVE-2017-15010 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-15010 advisory
- https://nodesecurity.io/advisories/525 advisory
- https://access.redhat.com/security/cve/CVE-2018-3728 advisory
- https://www.cve.org/CVERecord?id=CVE-2018-3728 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-3728 advisory