Description
ua-parser is a port of Browserscope's user agent parser. ua-parser is vulnerable to a ReDoS (Regular Expression Denial of Service) attack when given a specially crafted UserAgent header.
Remediation
References
https://nodesecurity.io/advisories/316
Related Vulnerabilities
CVE-2023-30515 Vulnerability in maven package io.jenkins.plugins:thycotic-devops-secrets-vault
CVE-2023-24188 Vulnerability in maven package com.bstek.ureport:ureport2-core
CVE-2018-25058 Vulnerability in npm package twitter-fetcher
CVE-2019-10341 Vulnerability in maven package io.jenkins.docker:docker-plugin