QID 983117
QID 983117: Nodejs (npm) Security Update for uap-core (GHSA-cmcx-xhr8-3w9p)
Security update has been released for uap-core to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Some regexes are vulnerable to regular expression denial of service (REDoS) due to overlapping capture groups. This allows remote attackers to overload a server by setting the User-Agent header in an HTTP(S) request to maliciously crafted long strings.
Solution
Please update uap-core to >= v0.7.3
Downstream packages such as uap-python, uap-ruby etc which depend upon uap-core follow different version schemes.
Downstream packages such as uap-python, uap-ruby etc which depend upon uap-core follow different version schemes.
Vendor References
- GHSA-cmcx-xhr8-3w9p -
github.com/advisories/GHSA-cmcx-xhr8-3w9p
CVEs related to QID 983117
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cmcx-xhr8-3w9p | uap-core |
|