googleapis / googleapis/google-cloud-node
Using the Vulnerable tough-cookie 4.0.4 as internal dependency.
Open
size: m
type: process
- Dominant language
- TypeScript
- Stars
- 3.2k
- Forks
- 712
- Avg merge
- 2d 3h
- Merged PRs (30d)
- 99
Description
Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using Cookie Jar in reject Public Suffixes=false mode.
- tough-cookie package used internally is outdated and poses a security risk.
- vulnerable tough-cookie version (4.0.4) and the recommended update (4.1.3).
Contributor guide
Assessment
This issue has not been assessed yet.