Description
Valine 1.4.14 allows remote attackers to cause a denial of service (application outage) by supplying a ua (aka User-Agent) value that only specifies the product and version.
Remediation
References
https://github.com/xCss/Valine/issues/366
Related Vulnerabilities
CVE-2020-7747 Vulnerability in npm package lightning-server
CVE-2023-29641 Vulnerability in npm package editor.md
CVE-2021-4264 Vulnerability in maven package org.webjars.bower:dustjs-linkedin
CVE-2022-31069 Vulnerability in npm package @finastra/nestjs-proxy
CVE-2017-18353 Vulnerability in npm package rendertron-middleware