Description
Valine 1.4.14 allows remote attackers to cause a denial of service (application outage) by supplying a ua (aka User-Agent) value that only specifies the product and version.
Remediation
References
https://github.com/xCss/Valine/issues/366
Related Vulnerabilities
CVE-2020-6422 Vulnerability in maven package org.webjars.npm:electron
CVE-2018-1306 Vulnerability in maven package org.apache.portals.pluto:portletv3annotateddemo
CVE-2020-27219 Vulnerability in maven package org.eclipse.hawkbit:hawkbit-update-server
CVE-2022-37258 Vulnerability in npm package steal
CVE-2021-37695 Vulnerability in maven package org.webjars.bowergithub.ckeditor:ckeditor4