Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-16030

Опубликовано: 15 апр. 2017
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Useragent is used to parse useragent headers. It uses several regular expressions to accomplish this. An attacker could edit their own headers, creating an arbitrarily long useragent string, causing the event loop and server to block. This affects Useragent 2.1.12 and earlier.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Mobile Application Platform 4fh-mbaasOut of support scope
Red Hat Mobile Application Platform 4fh-messagingOut of support scope
Red Hat Mobile Application Platform 4fh-metricsOut of support scope
Red Hat Mobile Application Platform 4fh-supercoreOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1588890nodejs-useragent: Regular expression Denial-of-Service via long UserAgent header

EPSS

Процентиль: 62%
0.00433
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 7 лет назад

Useragent is used to parse useragent headers. It uses several regular expressions to accomplish this. An attacker could edit their own headers, creating an arbitrarily long useragent string, causing the event loop and server to block. This affects Useragent 2.1.12 and earlier.

github
больше 7 лет назад

ReDoS via long UserAgent header in useragent

EPSS

Процентиль: 62%
0.00433
Низкий

7.5 High

CVSS3