Regular Expression Denial of Service (ReDoS) Affecting uap-core package, versions <0.6.0
Threat Intelligence
EPSS
0.78% (82nd
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-UAPCORE-72743
- published 30 Dec 2018
- disclosed 14 Dec 2018
- credit Lars Strojny lstrojny
Introduced: 14 Dec 2018
CVE-2018-20164 Open this link in a new tabHow to fix?
Upgrade uap-core
to version 0.6.0 or higher.
Overview
uap-core is a contains the core of BrowserScope's original user agent string parser: data collected over the years.
Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS).
References
CVSS Scores
version 3.1