在 Salesforce,我们深知数据的保密性、完整性和可用性对企业至关重要,而且我们非常重视数据保护。
发生了什么情况?
2023 年 6 月 1 日,一位安全研究人员发现一个 JavaScript 漏洞会影响 Salesforce Tough-Cookie 开源 NPM 项目。此漏洞允许恶意行为者将 Cookie 数据附加到全局命名空间,导致 Cookie 暴露给有权访问您的运行代码的人员。
Salesforce 如何解决此问题?
6 月 5 日,实施了修复程序,并将发行说明(在此获取)发布到 GitHub。6 月 29 日,发布了 CVE-2023-26136 来解决此漏洞,CVSS 评分为 6.5。
如何了解自己是否受影响?
要确定是否使用 Tough-Cookie NPM 包以及是否受此漏洞影响,请执行以下步骤:
如果不是以上这些情况,那么您的运行实例不会受到此漏洞的影响。
如果我受到影响,我应采取何种措施?
如果您确定受到此漏洞的影响,要消除对您的 Cookie 的未授权访问,请将 Tough-Cookie 升级到 4.1.3 版(在此获取)。或者,您可以更新代码,确保 CookieJar 的所有实例均将 rejectPublicSuffixes 设置为 true,或使用 MemoryCookieStore 的替代存储库。
如果我有疑问,我应该怎么做?
如果您有疑问,请通过帮助门户向支持部门提交个案。000395871

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.