Description
The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info).
Recommendation
Update the ua-parser-js
package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.7.23
- Patched version(s): 0.7.23
References
Related Issues
- Embedded malware in ua-parser-js - Vulnerability
- Remote Code Execution on click of <a> Link in markdown preview - CVE-2024-49362
- XSS vulnerability that affects bootstrap (GHSA-3mgp-fx93-9xv5) - CVE-2018-20676
- follow-redirects' Proxy-Authorization header kept across hosts - CVE-2024-28849
- Tags:
- npm
- ua-parser-js
Anything's wrong? Let us know Last updated on February 01, 2023