PT-2021-14414 · Uap-Core · Uap-Core

Published

2021-02-02

·

Updated

2024-02-08

·

CVE-2021-21317

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions uap-core versions prior to 0.11.0
Description The issue concerns regular expression denial of service (REDoS) due to overlapping capture groups in some regexes. This allows remote attackers to overload a server by setting the User-Agent header in an HTTP(S) request to maliciously crafted long strings.
Recommendations For versions prior to 0.11.0, update uap-core to version 0.11.0 or later. As a temporary workaround, consider restricting access to the User-Agent header in HTTP(S) requests until the issue is resolved.

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2021-21317
GHSA-P4PJ-MG4R-X6V4

Affected Products

Uap-Core