VDB
RHSA-2023:5542
RHSA-2023:5542
PUBLISHED
CVSS 6.5 MEDIUM
A flaw was found in the tough-cookie package which allows Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are initialized.
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift-logging/log-file-metric-exporter-rhel8@sha256:cc37a55b298253f983fb7b31d9194eac06343ef694ee5979e9f43147ad0218a8_arm64 as a component of RHOL 5.5 for RHEL 8 | openshift-logging/log-file-metric-exporter-rhel8@sha256:cc37a55b298253f983fb7b31d9194eac06343ef694ee5979e9f43147ad0218a8_arm64, *, * |
| Red Hat | openshift-logging/elasticsearch-rhel8-operator@sha256:ceb0851250bd48ca908f038ae6a9df08530cc876054f3e8447c3b988b18da2a2_s390x as a component of RHOL 5.5 for RHEL 8 | openshift-logging/elasticsearch-rhel8-operator@sha256:ceb0851250bd48ca908f038ae6a9df08530cc876054f3e8447c3b988b18da2a2_s390x, openshift-logging/elasticsearch-rhel8-operator@sha256:ceb0851250bd48ca908f038ae6a9df08530cc876054f3e8447c3b988b18da2a2_s390x, openshift-logging/elasticsearch-rhel8-operator@sha256:ceb0851250bd48ca908f038ae6a9df08530cc876054f3e8447c3b988b18da2a2_s390x |
| Red Hat | openshift-logging/loki-rhel8-operator@sha256:cc3200d2493d1ae32e07e273599708dd0d3be7ff4c82889feb33ed9c5da48de2_s390x as a component of RHOL 5.5 for RHEL 8 | *, openshift-logging/loki-rhel8-operator@sha256:cc3200d2493d1ae32e07e273599708dd0d3be7ff4c82889feb33ed9c5da48de2_s390x, openshift-logging/loki-rhel8-operator@sha256:cc3200d2493d1ae32e07e273599708dd0d3be7ff4c82889feb33ed9c5da48de2_s390x |
| Red Hat | openshift-logging/logging-loki-rhel8@sha256:53d89f40f8362c922a5c50cc78b58e9573bd97cb67ec7a8520e161b421c78f3e_amd64 as a component of RHOL 5.5 for RHEL 8 | *, *, * |
| salesforce | tough-cookie | |
| Red Hat | openshift-logging/logging-view-plugin-rhel8@sha256:257c8f58c651c6b6138fe4f4b3bb26f8f4368802691f5c52c0d110a95689caf2_ppc64le as a component of RHOL 5.5 for RHEL 8 | openshift-logging/logging-view-plugin-rhel8@sha256:257c8f58c651c6b6138fe4f4b3bb26f8f4368802691f5c52c0d110a95689caf2_ppc64le, openshift-logging/logging-view-plugin-rhel8@sha256:257c8f58c651c6b6138fe4f4b3bb26f8f4368802691f5c52c0d110a95689caf2_ppc64le, * |
| Red Hat | openshift-logging/logging-curator5-rhel8@sha256:5b23d637b76de7e4f557a8c3dc46b30021666a0425130586697a4c18cbe0ba10_ppc64le as a component of RHOL 5.5 for RHEL 8 | openshift-logging/logging-curator5-rhel8@sha256:5b23d637b76de7e4f557a8c3dc46b30021666a0425130586697a4c18cbe0ba10_ppc64le, openshift-logging/logging-curator5-rhel8@sha256:5b23d637b76de7e4f557a8c3dc46b30021666a0425130586697a4c18cbe0ba10_ppc64le, openshift-logging/logging-curator5-rhel8@sha256:5b23d637b76de7e4f557a8c3dc46b30021666a0425130586697a4c18cbe0ba10_ppc64le |
| Red Hat | openshift-logging/vector-rhel8@sha256:ce46f671b48687a3b2b54583595eff8654ee219b6606230c497dc78c4ef6e9a0_amd64 as a component of RHOL 5.5 for RHEL 8 | openshift-logging/vector-rhel8@sha256:ce46f671b48687a3b2b54583595eff8654ee219b6606230c497dc78c4ef6e9a0_amd64, openshift-logging/vector-rhel8@sha256:ce46f671b48687a3b2b54583595eff8654ee219b6606230c497dc78c4ef6e9a0_amd64, openshift-logging/vector-rhel8@sha256:ce46f671b48687a3b2b54583595eff8654ee219b6606230c497dc78c4ef6e9a0_amd64 |
| Red Hat | openshift-logging/lokistack-gateway-rhel8@sha256:c0c815822696f7944662720a07e238d23c86f2d788aef93857bd04952a341d8d_arm64 as a component of RHOL 5.5 for RHEL 8 | *, *, * |
| Red Hat | openshift-logging/elasticsearch-rhel8-operator@sha256:07f46c6182126014df275c8cf64a2864ae1d887e58228c2c48da5809315e15fc_ppc64le as a component of RHOL 5.5 for RHEL 8 | *, *, * |
| Red Hat | openshift-logging/kibana6-rhel8@sha256:87a32dd0769e887e2c11766e7564d4d161f180019d28dd78d99fe48e18c53ac5_ppc64le as a component of RHOL 5.5 for RHEL 8 | *, *, openshift-logging/kibana6-rhel8@sha256:87a32dd0769e887e2c11766e7564d4d161f180019d28dd78d99fe48e18c53ac5_ppc64le |
| Red Hat | openshift-logging/fluentd-rhel8@sha256:c0c053caabd85aea33f8b69bda2739a9288ed8b48554932c431bd6f5615a510b_s390x as a component of RHOL 5.5 for RHEL 8 | openshift-logging/fluentd-rhel8@sha256:c0c053caabd85aea33f8b69bda2739a9288ed8b48554932c431bd6f5615a510b_s390x, openshift-logging/fluentd-rhel8@sha256:c0c053caabd85aea33f8b69bda2739a9288ed8b48554932c431bd6f5615a510b_s390x, openshift-logging/fluentd-rhel8@sha256:c0c053caabd85aea33f8b69bda2739a9288ed8b48554932c431bd6f5615a510b_s390x |
| Red Hat | openshift-logging/log-file-metric-exporter-rhel8@sha256:8dfa5d26fa43a3baa36e8eac831868c4a26a177b42af704ccde7a2a3c7cbc7ad_ppc64le as a component of RHOL 5.5 for RHEL 8 | *, openshift-logging/log-file-metric-exporter-rhel8@sha256:8dfa5d26fa43a3baa36e8eac831868c4a26a177b42af704ccde7a2a3c7cbc7ad_ppc64le, openshift-logging/log-file-metric-exporter-rhel8@sha256:8dfa5d26fa43a3baa36e8eac831868c4a26a177b42af704ccde7a2a3c7cbc7ad_ppc64le |
| Red Hat | openshift-logging/elasticsearch-rhel8-operator@sha256:5ebb73023691a43b9bfc53543d87fc143ec11bbb25d5035bd5cb29e9526203b1_arm64 as a component of RHOL 5.5 for RHEL 8 | *, *, * |
| Red Hat | openshift-logging/cluster-logging-rhel8-operator@sha256:51601c319a847410dd67dded9bfc3e177d607f9bbd955e40da14c0a6e18775d9_s390x as a component of RHOL 5.5 for RHEL 8 | openshift-logging/cluster-logging-rhel8-operator@sha256:51601c319a847410dd67dded9bfc3e177d607f9bbd955e40da14c0a6e18775d9_s390x, openshift-logging/cluster-logging-rhel8-operator@sha256:51601c319a847410dd67dded9bfc3e177d607f9bbd955e40da14c0a6e18775d9_s390x, openshift-logging/cluster-logging-rhel8-operator@sha256:51601c319a847410dd67dded9bfc3e177d607f9bbd955e40da14c0a6e18775d9_s390x |
| Red Hat | openshift-logging/cluster-logging-rhel8-operator@sha256:09686a47d73e381c80003714147137a3d3b1d9672d507d26c35a486e17f95938_ppc64le as a component of RHOL 5.5 for RHEL 8 | openshift-logging/cluster-logging-rhel8-operator@sha256:09686a47d73e381c80003714147137a3d3b1d9672d507d26c35a486e17f95938_ppc64le, openshift-logging/cluster-logging-rhel8-operator@sha256:09686a47d73e381c80003714147137a3d3b1d9672d507d26c35a486e17f95938_ppc64le, * |
| Red Hat | openshift-logging/elasticsearch-proxy-rhel8@sha256:97af66b3e1fb61379c42d1e9f456f1e831595dd22f62dc70be2da10c8ea9d780_arm64 as a component of RHOL 5.5 for RHEL 8 | openshift-logging/elasticsearch-proxy-rhel8@sha256:97af66b3e1fb61379c42d1e9f456f1e831595dd22f62dc70be2da10c8ea9d780_arm64, openshift-logging/elasticsearch-proxy-rhel8@sha256:97af66b3e1fb61379c42d1e9f456f1e831595dd22f62dc70be2da10c8ea9d780_arm64, openshift-logging/elasticsearch-proxy-rhel8@sha256:97af66b3e1fb61379c42d1e9f456f1e831595dd22f62dc70be2da10c8ea9d780_arm64 |
| Red Hat | openshift-logging/logging-loki-rhel8@sha256:f7b33ceb2433364c87f6f035a38c467e54814c3973873bd3d6dfdf9b99d2d278_arm64 as a component of RHOL 5.5 for RHEL 8 | openshift-logging/logging-loki-rhel8@sha256:f7b33ceb2433364c87f6f035a38c467e54814c3973873bd3d6dfdf9b99d2d278_arm64, openshift-logging/logging-loki-rhel8@sha256:f7b33ceb2433364c87f6f035a38c467e54814c3973873bd3d6dfdf9b99d2d278_arm64, openshift-logging/logging-loki-rhel8@sha256:f7b33ceb2433364c87f6f035a38c467e54814c3973873bd3d6dfdf9b99d2d278_arm64 |
| Red Hat | openshift-logging/logging-view-plugin-rhel8@sha256:0647ae6a93087832d1529a9d56b2157a798efafc4645b8bcf1b49f1d43634978_amd64 as a component of RHOL 5.5 for RHEL 8 | *, *, openshift-logging/logging-view-plugin-rhel8@sha256:0647ae6a93087832d1529a9d56b2157a798efafc4645b8bcf1b49f1d43634978_amd64 |
| Red Hat | openshift-logging/log-file-metric-exporter-rhel8@sha256:0dbe15a2497d60ed8c108be2afe0f7ad750ee7502c1180273767f0e5449943c6_s390x as a component of RHOL 5.5 for RHEL 8 | *, openshift-logging/log-file-metric-exporter-rhel8@sha256:0dbe15a2497d60ed8c108be2afe0f7ad750ee7502c1180273767f0e5449943c6_s390x, * |
…and 109 more
Timeline
- Oct 24, 2023 CVE Published
- Apr 26, 2026 Distribution Patch
- Apr 26, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 5, 2026 Security Advisory
- May 16, 2026 Distribution Patch
- Jul 25, 2026 Security Advisory
- Aug 7, 2026 CVE Updated
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-39325 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog exploit
- https://nvd.nist.gov/vuln/detail/CVE-2023-26136 advisory
- https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/security/cve/CVE-2023-26136 advisory
- https://github.com/salesforce/tough-cookie/releases/tag/v4.1.3 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2219310 issue
- https://access.redhat.com/errata/RHSA-2023:5542 advisory
- https://github.com/salesforce/tough-cookie/issues/282 advisory
- https://lists.debian.org/debian-lts-announce/2023/07/msg00010.html advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-44487 advisory
- https://security.snyk.io/vuln/SNYK-JS-TOUGHCOOKIE-5672873 advisory
- https://pkg.go.dev/vuln/GO-2023-2102 advisory
- https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ advisory
- https://access.redhat.com/security/vulnerabilities/RHSB-2023-003 advisory
- https://github.com/dotnet/announcements/issues/277 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2243296 issue
- https://www.cve.org/CVERecord?id=CVE-2023-26136 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-44487 advisory
…and 8 more