HIGH7.5
GHSA-p4pj-mg4r-x6v4
Denial of Service in uap-core
Quick fix
GHSA-p4pj-mg4r-x6v4 — uap-core: upgrade to the fixed version with the command below.
npm install uap-core@0.11.0Details
## Impact
Some regexes are vulnerable to regular expression denial of service (REDoS) due to overlapping capture groups. This allows remote attackers to overload a server by setting the User-Agent header in an HTTP(S) request to maliciously crafted long strings.
## Patches
Please update uap-core to >= v0.11.0
Downstream packages such as uap-python, uap-ruby etc which depend upon uap-core follow different version schemes.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/ua-parser/uap-core/security/advisories/GHSA-p4pj-mg4r-x6v4[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2021-21317[ADVISORY]
- https://github.com/ua-parser/uap-core/commit/dc9925d458214cfe87b93e35346980612f6ae96c[WEB]
- https://github.com/ua-parser/uap-core[PACKAGE]
- https://www.npmjs.com/package/uap-core[WEB]