First published: Sat Sep 12 2020(Updated: )
A flaw was found in nodejs-ua-parser-js. The software is vulnerable to Regular Expression Denial of Service (ReDoS) via the regex for Redmi Phones and Mi Pad Tablets UA.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/nodejs-ua-parser-js | <0.7.22 | 0.7.22 |
redhat/ovirt-engine-ui-extensions | <0:1.2.7-1.el8e | 0:1.2.7-1.el8e |
redhat/ovirt-web-ui | <0:1.7.2-1.el8e | 0:1.7.2-1.el8e |
Ua-parser-js Project Ua-parser-js | <0.7.22 | |
Oracle Communications Cloud Native Core Network Function Cloud Native Environment | =1.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-7733.
The severity of CVE-2020-7733 is high.
The software packages affected by CVE-2020-7733 are nodejs-ua-parser-js, ovirt-engine-ui-extensions, and ovirt-web-ui.
To fix CVE-2020-7733, update nodejs-ua-parser-js package to version 0.7.22 or higher.
More information about CVE-2020-7733 can be found at the following references: [Link 1](https://github.com/faisalman/ua-parser-js/commit/233d3bae22a795153a7e6638887ce159c63e557d), [Link 2](https://snyk.io/vuln/SNYK-JS-UAPARSERJS-610226), [Link 3](https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-674665)