QID 375999
Date Published: 2021-11-01
QID 375999: NPM Package Ua-Parser-Js Remote Code Execution (RCE) Vulnerability
UAParser.js:JavaScript library to detect Browser, Engine, OS, CPU, and Device type/model from User-Agent data with relatively small footprint (~17KB minified, ~6KB gzipped) that can be used either in browser (client-side) or node.js (server-side).
Affected versions:
ua-parser-js 0.7.29
ua-parser-js 0.8.0
ua-parser-js 1.0.0
QID Detection logic:(Authenticated)
It will execute command npm list | grep 'ua-parser-js' command to check the ua-parser-js version
Any computer that has this package installed or running should be considered fully compromised.
Solution
Customers are advised to update ua-parser-js package 0.7.30, 0.8.1 and 1.0.1 or later . Please refer the Vendor advisory link ua-parser-js
Vendor References
- ua-parser-js -
github.com/advisories/GHSA-pjwm-rvh2-c87w
CVEs related to QID 375999
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-pjwm-rvh2-c87w |
|