Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-7733

Опубликовано: 12 сент. 2020
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

The package ua-parser-js before 0.7.22 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex for Redmi Phones and Mi Pad Tablets UA.

A flaw was found in nodejs-ua-parser-js. The software is vulnerable to Regular Expression Denial of Service (ReDoS) via the regex for Redmi Phones and Mi Pad Tablets UA.

Отчет

Red Hat OpenShift Container Platform 4 delivers the kibana package where the ua-parser-js library is bundled, but during the update to container first (to openshift4/ose-logging-kibana6) the dependency was removed and hence kibana package is marked as wontfix. This may be fixed in the future.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Distributed Tracing Jaeger 1distributed-tracing/jaeger-all-in-one-rhel7Fix deferred
Distributed Tracing Jaeger 1distributed-tracing/jaeger-query-rhel7Fix deferred
OpenShift Service Mesh 1servicemesh-grafanaNot affected
Red Hat Advanced Cluster Management for Kubernetes 2nodejs-ua-parser-jsFix deferred
Red Hat OpenShift Container Platform 3.11kibanaFix deferred
Red Hat OpenShift Container Platform 3.11openshift3/grafanaNot affected
Red Hat OpenShift Container Platform 4kibanaWill not fix
Red Hat OpenShift Container Platform 4openshift4/ose-grafanaNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-logging-kibana6Fix deferred
Red Hat Storage 3grafanaAffected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1879733nodejs-ua-parser-js: Regular expression denial of service via the regex

EPSS

Процентиль: 79%
0.01196
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

The package ua-parser-js before 0.7.22 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex for Redmi Phones and Mi Pad Tablets UA.

CVSS3: 7.5
nvd
больше 5 лет назад

The package ua-parser-js before 0.7.22 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex for Redmi Phones and Mi Pad Tablets UA.

CVSS3: 7.5
debian
больше 5 лет назад

The package ua-parser-js before 0.7.22 are vulnerable to Regular Expre ...

CVSS3: 7.5
github
больше 4 лет назад

Regular Expression Denial of Service in ua-parser-js

CVSS3: 7.5
fstec
больше 4 лет назад

Уязвимость библиотеки ua-parser-js прикладного программного обеспечения Аврора Центр, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 79%
0.01196
Низкий

7.5 High

CVSS3