Back

HIGH

Regular Expression Denial of Service (ReDoS)

Published Dec 11, 2020

Description

The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info).

Affected products

Remediation

Red Hat statement

Red Hat OpenShift Container Platform 4 delivers the kibana package where the ua-parser-js library is bundled, but during the update to container first (to openshift4/ose-logging-kibana6) the dependency was removed and hence kibana package is marked as wontfix. This may be fixed in the future. Red Hat Ceph Storage 3 and 4 ship a version of grafana that pulls a version of ua-parser-js (0.7.9) that uses the affected code.

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner snyk
Published Dec 11, 2020
Updated Sep 16, 2024
Reserved Jan 21, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Oct 29, 2020
ENISA EUVD
Assigner snyk
Published Dec 11, 2020
Updated Sep 16, 2024
Exploited since n/a
EUVD-2022-0786 GHSA-394C-5J6W-4XMX