The package ua-parser-js before 0.7.22 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex for Redmi Phones and Mi Pad Tablets UA.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://snyk.io/vuln/SNYK-JS-UAPARSERJS-610226 | third party advisory exploit |
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-674665 | third party advisory exploit |
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBFAISALMAN-674666 | third party advisory exploit |
https://github.com/faisalman/ua-parser-js/commit/233d3bae22a795153a7e6638887ce159c63e557d | third party advisory patch |
https://www.oracle.com//security-alerts/cpujul2021.html | third party advisory |