Description
Valine 1.4.14 allows remote attackers to cause a denial of service (application outage) by supplying a ua (aka User-Agent) value that only specifies the product and version.
Remediation
References
https://github.com/xCss/Valine/issues/366
Related Vulnerabilities
CVE-2020-8441 Vulnerability in maven package org.jyaml:jyaml
CVE-2021-46361 Vulnerability in maven package info.magnolia:magnolia-core
CVE-2021-32860 Vulnerability in npm package izimodal
CVE-2023-43494 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2021-23346 Vulnerability in maven package org.webjars.npm:html-parse-stringify2