HIGH 7.5
GHSA-662x-fhqg-9p8v
Regular Expression Denial of Service in ua-parser-js
Details
The package ua-parser-js before 0.7.22 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex for Redmi Phones and Mi Pad Tablets UA.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-7733 [ADVISORY]
- https://github.com/faisalman/ua-parser-js/commit/233d3bae22a795153a7e6638887ce159c63e557d [WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBFAISALMAN-674666 [WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-674665 [WEB]
- https://snyk.io/vuln/SNYK-JS-UAPARSERJS-610226 [WEB]
- https://www.oracle.com//security-alerts/cpujul2021.html [WEB]