Description
Valine is a fast, simple & powerful comment system. Valine 1.4.14 allows remote attackers to cause a denial of service (application outage) by supplying a ua (aka User-Agent) value that only specifies the product and version.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.4.14
References
Could your website be exposed too?
SmartScanner can check your website for Denial of service in Valine and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Regular Expression Denial of Service (ReDoS) in ua-parser-js - CVE-2021-27292
- Regular expression Denial of Service in multiple packages - CVE-2021-21391
- semver-regex Regular Expression Denial of Service (ReDOS) - CVE-2021-3795
- Regular Expression Denial of Service (ReDOS) - color-string - CVE-2021-29060
You might also like:
See something that needs correcting? Let us knowUpdated February 01, 2023


