CVE-2020-7793
published 2020-12-11CVE-2020-7793: The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info).
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.88%
89.1th percentile
The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-ua-parser-js | < node-ua-parser-js 0.7.23+ds-1 (bookworm) | node-ua-parser-js 0.7.23+ds-1 (bookworm) |
| siemens | sinec_ins | < 1.0 | 1.0 |
| siemens | sinec_ins | — | — |
| ua-parser-js_project | ua-parser-js | < 0.7.23 | 0.7.23 |
| ua-parser-js_project | ua-parser-js | >= 0 < 0.7.23 | 0.7.23 |
| ua-parser-js_project | ua-parser-js | >= unspecified < 0.7.23 | 0.7.23 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SINEC INS
cisa_ics·2022-09-15·CVSS 7.8
[HIGH] Siemens SINEC INS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEC INS
Last RevisedSeptember 15, 2022
Alert CodeICSA-22-258-05
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.8
- ATTENTION: Exploitable remotely/Low attack complexity
- Vendor: Siemens
- Equipment: SINEC INS
- Vulnerabilities: Improper Input Validation, Integer Overflow or Wraparound, Uncontrolled Resource Consumption, Command Injection, Inadequate Encryption Strength, Missing Encryption of Sensitive Data, Improper Restriction of Operations Within the Bounds of a Memory Buffer, Exposure of Private Personal Information to an Unauthorized Actor, Open Redirect, Improper Resour
Red Hat
nodejs-ua-parser-js: ReDoS in multiple regexes
vendor_redhat·2020-10-29·CVSS 7.5
CVE-2020-7793 [HIGH] CWE-400 nodejs-ua-parser-js: ReDoS in multiple regexes
nodejs-ua-parser-js: ReDoS in multiple regexes
The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info).
A flaw was found in nodejs-ua-parser-js. The software is vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes.
Statement: Red Hat OpenShift Container Platform 4 delivers the kibana package where the ua-parser-js library is bundled, but during the update to container first (to openshift4/ose-logging-kibana6) the dependency was removed and hence kibana package is marked as wontfix. This may be fixed in the future.
Red Hat Ceph Storage 3 and 4 ship a version of grafana that pulls a version of ua-parser-js (0.7.9) that uses the affected code.
Package: distributed-
Debian
CVE-2020-7793: node-ua-parser-js - The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Deni...
vendor_debian·2020·CVSS 7.5
CVE-2020-7793 [HIGH] CVE-2020-7793: node-ua-parser-js - The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Deni...
The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info).
Scope: local
bookworm: resolved (fixed in 0.7.23+ds-1)
bullseye: resolved (fixed in 0.7.23+ds-1)
forky: resolved (fixed in 0.7.23+ds-1)
sid: resolved (fixed in 0.7.23+ds-1)
trixie: resolved (fixed in 0.7.23+ds-1)
OSV
ua-parser-js Regular Expression Denial of Service vulnerability
osv·2022-02-09
CVE-2020-7793 [HIGH] ua-parser-js Regular Expression Denial of Service vulnerability
ua-parser-js Regular Expression Denial of Service vulnerability
The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info).
GHSA
ua-parser-js Regular Expression Denial of Service vulnerability
ghsa·2022-02-09
CVE-2020-7793 [HIGH] CWE-400 ua-parser-js Regular Expression Denial of Service vulnerability
ua-parser-js Regular Expression Denial of Service vulnerability
The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info).
OSV
CVE-2020-7793: The package ua-parser-js before 0
osv·2020-12-11·CVSS 7.5
CVE-2020-7793 [HIGH] CVE-2020-7793: The package ua-parser-js before 0
The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdfhttps://github.com/faisalman/ua-parser-js/commit/6d1f26df051ba681463ef109d36c9cf0f7e32b18https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBFAISALMAN-1050388https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1050387https://snyk.io/vuln/SNYK-JS-UAPARSERJS-1023599https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdfhttps://github.com/faisalman/ua-parser-js/commit/6d1f26df051ba681463ef109d36c9cf0f7e32b18https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBFAISALMAN-1050388https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1050387https://snyk.io/vuln/SNYK-JS-UAPARSERJS-1023599
2020-12-11
Published