PT-2020-6066 · Unknown · Ua-Parser-Js

Miguel De Moura

+1

·

Published

2020-12-11

·

Updated

2022-09-13

·

CVE-2020-7793

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ua-parser-js versions prior to 0.7.23
Description The issue is related to an uncontrolled resource consumption vulnerability in the ua-parser-js library, which can be exploited by a remote attacker to cause a denial of service. The vulnerability is due to Regular Expression Denial of Service (ReDoS) in multiple regexes.
Recommendations For versions prior to 0.7.23, update to version 0.7.23 or later to resolve the issue. As a temporary workaround, consider restricting the use of the vulnerable regexes until a patch is available.

Exploit

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2021-02878
CVE-2020-7793
GHSA-394C-5J6W-4XMX
SNYK-JAVA-ORGWEBJARSBOWERGITHUBFAISALMAN-1050388
SNYK-JAVA-ORGWEBJARSNPM-1050387
SNYK-JS-UAPARSERJS-1023599

Affected Products

Ua-Parser-Js