googleapis / googleapis/google-cloud-node

Using the Vulnerable tough-cookie 4.0.4 as internal dependency.

Open
#5,150 0 comments 0 reactions 0 assignees View on GitHub
size: m type: process
Dominant language
TypeScript
Stars
3.2k
Forks
712
Avg merge
2d 3h
Merged PRs (30d)
99

Description

Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using Cookie Jar in reject Public Suffixes=false mode.

- tough-cookie package used internally is outdated and poses a security risk.
- vulnerable tough-cookie version (4.0.4) and the recommended update (4.1.3).

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.