First published: Tue May 24 2022(Updated: )
A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0. It has been rated as critical. This issue affects the crypto mining component which introduces a backdoor. Upgrading to version 0.7.30, 0.8.1 and 1.0.1 is able to address this issue. It is recommended to upgrade the affected component.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ua-parser-js Project Ua-parser-js | =0.7.29 | |
Ua-parser-js Project Ua-parser-js | =0.8.0 | |
Ua-parser-js Project Ua-parser-js | =1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-4229 is a critical vulnerability found in ua-parser-js versions 0.7.29, 0.8.0, and 1.0.0 that affects the crypto mining component, introducing a backdoor.
CVE-2021-4229 has a severity rating of 8.8 (high).
The affected software is ua-parser-js version 0.7.29, 0.8.0, and 1.0.0.
To address CVE-2021-4229, it is recommended to upgrade to version 0.7.30, 0.8.1, or 1.0.1 of ua-parser-js.
You can find more information about CVE-2021-4229 at the following references: [GitHub Advisory](https://github.com/advisories/GHSA-pjwm-rvh2-c87w), [GitHub Issue](https://github.com/faisalman/ua-parser-js/issues/536), [VulDB](https://vuldb.com/?id.185453)