QID 982672
QID 982672: Nodejs (npm) Security Update for ua-parser-js (GHSA-78cj-fxph-m83p)
ua-parser-js >= 0.7.14, fixed in 0.7.24, uses a regular expression which is vulnerable to denial of service. If an attacker sends a malicious User-Agent header, ua-parser-js will get stuck processing it for an extended period of time.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-78cj-fxph-m83p for updates pertaining to this vulnerability.
Vendor References
- GHSA-78cj-fxph-m83p -
github.com/advisories/GHSA-78cj-fxph-m83p
CVEs related to QID 982672
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-78cj-fxph-m83p | ua-parser-js |
|