Description
Valine is a fast, simple & powerful comment system. Valine 1.4.14 allows remote attackers to cause a denial of service (application outage) by supplying a ua (aka User-Agent) value that only specifies the product and version.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.4.14
References
Related Issues
- Regular Expression Denial of Service (ReDoS) in ua-parser-js - CVE-2021-27292
- Regular expression Denial of Service in multiple packages - CVE-2021-21391
- semver-regex Regular Expression Denial of Service (ReDOS) - CVE-2021-3795
- Regular Expression Denial of Service (ReDOS) - color-string - CVE-2021-29060
You might also like:
- Tags:
- npm
- valine
Anything's wrong? Let us know Last updated on February 01, 2023


