Description
Valine 1.4.14 allows remote attackers to cause a denial of service (application outage) by supplying a ua (aka User-Agent) value that only specifies the product and version.
Remediation
References
https://github.com/xCss/Valine/issues/366
Related Vulnerabilities
CVE-2023-24057 Vulnerability in maven package ca.uhn.hapi.fhir:org.hl7.fhir.convertors
CVE-2020-8127 Vulnerability in npm package reveal.js
CVE-2022-45388 Vulnerability in maven package net.praqma:config-rotator
CVE-2022-22984 Vulnerability in npm package snyk-mvn-plugin
CVE-2022-28366 Vulnerability in maven package net.sourceforge.nekohtml:nekohtml