Description
This affects the package es6-crawler-detect before 3.1.3. No limitation of user agent string length supplied to regex operators.
Remediation
References
https://github.com/JefferyHus/es6-crawler-detect/pull/27
https://snyk.io/vuln/SNYK-JS-ES6CRAWLERDETECT-1051529
Related Vulnerabilities
CVE-2023-48241 Vulnerability in maven package org.xwiki.platform:xwiki-platform-search-solr-query
CVE-2021-22144 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2022-31183 Vulnerability in maven package co.fs2:fs2-io_sjs1_2.12
CVE-2020-26272 Vulnerability in maven package org.webjars.npm:electron
CVE-2021-32659 Vulnerability in npm package matrix-appservice-bridge