Description
Valine 1.4.14 allows remote attackers to cause a denial of service (application outage) by supplying a ua (aka User-Agent) value that only specifies the product and version.
Remediation
References
https://github.com/xCss/Valine/issues/366
Related Vulnerabilities
CVE-2023-3691 Vulnerability in npm package layui
CVE-2021-20293 Vulnerability in maven package org.jboss.resteasy:resteasy-core
CVE-2021-21391 Vulnerability in npm package @ckeditor/ckeditor5-image
CVE-2023-26136 Vulnerability in npm package tough-cookie
CVE-2023-3163 Vulnerability in maven package com.ruoyi:ruoyi-common