Bug 32114 - nodejs-tough-cookie new security issue CVE-2023-26136
Summary: nodejs-tough-cookie new security issue CVE-2023-26136
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2023-07-17 21:57 CEST by David Walser
Modified: 2024-03-22 01:21 CET (History)
4 users (show)

See Also:
Source RPM: nodejs-tough-cookie-2.3.4-5.mga9.src.rpm
CVE: CVE-2023-26136
Status comment:


Attachments

Description David Walser 2023-07-17 21:57:24 CEST
Debian-LTS has issued an advisory on July 10:
https://www.debian.org/lts/security/2023/dla-3488

The issue is fixed upstream in 4.1.3.

Mageia 8 is also affected.
David Walser 2023-07-17 21:58:02 CEST

Whiteboard: (none) => MGA8TOO
Status comment: (none) => Fixed upstream in 4.1.3

Comment 1 Lewis Smith 2023-07-19 20:58:27 CEST
This is one for Stig (last touched 5y ago!).

Assignee: bugsquad => smelror

Comment 2 Nicolas Salguero 2024-03-19 11:48:59 CET
Suggested advisory:
========================

The updated package fixes a security vulnerability:

Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are initialized. (CVE-2023-26136)

References:
https://www.debian.org/lts/security/2023/dla-3488
========================

Updated package in core/updates_testing:
========================
nodejs-tough-cookie-2.3.4-5.1.mga9

from SRPM:
nodejs-tough-cookie-2.3.4-5.1.mga9.src.rpm

Assignee: smelror => qa-bugs
Version: Cauldron => 9
Status comment: Fixed upstream in 4.1.3 => (none)
Status: NEW => ASSIGNED
Whiteboard: MGA8TOO => (none)
CC: (none) => nicolas.salguero
CVE: (none) => CVE-2023-26136

katnatek 2024-03-19 19:58:18 CET

Keywords: (none) => advisory

Comment 3 katnatek 2024-03-21 20:35:07 CET
RH mageia 9 x86_64

Install current package

LC_ALL=C urpmi nodejs-tough-cookie

    https://mirror.math.princeton.edu/pub/mageia/distrib/9/x86_64/media/core/release/nodejs-tough-cookie-2.3.4-5.mga9.noarch.rpm
installing nodejs-tough-cookie-2.3.4-5.mga9.noarch.rpm from /var/cache/urpmi/rpms                                       
Preparing...                     ######################################################################################
      1/1: nodejs-tough-cookie   ######################################################################################


Update to testing version

LC_ALL=C urpmi --auto --auto-update 
medium "QA Testing (32-bit)" is up-to-date
medium "QA Testing (64-bit)" is up-to-date
medium "Core Release (distrib1)" is up-to-date
medium "Core Updates (distrib3)" is up-to-date
medium "Nonfree Release (distrib11)" is up-to-date
medium "Nonfree Updates (distrib13)" is up-to-date
medium "Tainted Release (distrib21)" is up-to-date
medium "Tainted Updates (distrib23)" is up-to-date
medium "Core 32bit Release (distrib31)" is up-to-date
medium "Core 32bit Updates (distrib32)" is up-to-date
medium "Nonfree 32bit Release (distrib36)" is up-to-date
medium "Tainted 32bit Release (distrib41)" is up-to-date
medium "Tainted 32bit Updates (distrib42)" is up-to-date


installing nodejs-tough-cookie-2.3.4-5.1.mga9.noarch.rpm from //home/katnatek/qa-testing/x86_64
Preparing...                     ######################################################################################
      1/1: nodejs-tough-cookie   ######################################################################################
      1/1: removing nodejs-tough-cookie-2.3.4-5.mga9.noarch
                                 ######################################################################################


Remove package

LC_ALL=C urpme nodejs-tough-cookie
removing nodejs-tough-cookie-2.3.4-5.1.mga9.noarch
removing package nodejs-tough-cookie-2.3.4-5.1.mga9.noarch
      1/1: removing nodejs-tough-cookie-2.3.4-5.1.mga9.noarch
                                 ######################################################################################
katnatek 2024-03-21 20:35:23 CET

CC: (none) => andrewsfarm

Comment 4 katnatek 2024-03-21 20:35:59 CET
Not previous rounds of the package
Give OK

Whiteboard: (none) => MGA9-64-OK

Comment 5 Thomas Andrews 2024-03-21 22:21:54 CET
Validating.

CC: (none) => sysadmin-bugs
Keywords: (none) => validated_update

Comment 6 Dan Fandrich 2024-03-22 00:29:18 CET
Assuming the version number is correct as-is and shouldn't be rotated right once to 1.2.3-4.5 :-)

CC: (none) => dan

Comment 7 Mageia Robot 2024-03-22 01:21:14 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2024-0080.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.