Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-5243

Опубликовано: 21 фев. 2020
Источник: nvd
CVSS3: 5.7
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

uap-core before 0.7.3 is vulnerable to a denial of service attack when processing crafted User-Agent strings. Some regexes are vulnerable to regular expression denial of service (REDoS) due to overlapping capture groups. This allows remote attackers to overload a server by setting the User-Agent header in an HTTP(S) request to maliciously crafted long strings. This has been patched in uap-core 0.7.3.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:uap-core_project:uap-core:*:*:*:*:*:node.js:*:*
Версия до 0.7.3 (исключая)

EPSS

Процентиль: 74%
0.00805
Низкий

5.7 Medium

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20
CWE-1333

Связанные уязвимости

CVSS3: 5.7
ubuntu
почти 6 лет назад

uap-core before 0.7.3 is vulnerable to a denial of service attack when processing crafted User-Agent strings. Some regexes are vulnerable to regular expression denial of service (REDoS) due to overlapping capture groups. This allows remote attackers to overload a server by setting the User-Agent header in an HTTP(S) request to maliciously crafted long strings. This has been patched in uap-core 0.7.3.

CVSS3: 5.7
debian
почти 6 лет назад

uap-core before 0.7.3 is vulnerable to a denial of service attack when ...

CVSS3: 5.7
github
почти 6 лет назад

Denial of Service in uap-core when processing crafted User-Agent strings

EPSS

Процентиль: 74%
0.00805
Низкий

5.7 Medium

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20
CWE-1333