Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-25927

Опубликовано: 22 янв. 2023
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regular Expression Denial of Service (ReDoS) via the trim() function.

A flaw was found in ua-parser-js. This issue could allow a malicious user to trigger a regular expression denial of service (ReDoS) via the trim() function.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and ServicesodoNot affected
OpenShift Service Mesh 2.1servicemesh-grafanaWill not fix
Red Hat Ceph Storage 3grafanaOut of support scope
Red Hat Decision Manager 7ua-parser-jsOut of support scope
Red Hat Discovery 1discovery-server-containerNot affected
Red Hat Enterprise Linux 6firefoxNot affected
Red Hat Enterprise Linux 7firefoxNot affected
Red Hat Enterprise Linux 7subscription-managerNot affected
Red Hat Enterprise Linux 8389-ds:1.4/389-ds-baseNot affected
Red Hat Enterprise Linux 8cockpitNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1333
https://bugzilla.redhat.com/show_bug.cgi?id=2165020ua-parser-js: ReDoS vulnerability via the trim() function

EPSS

Процентиль: 81%
0.01515
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 3 лет назад

Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regular Expression Denial of Service (ReDoS) via the trim() function.

CVSS3: 5.3
nvd
около 3 лет назад

Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regular Expression Denial of Service (ReDoS) via the trim() function.

CVSS3: 5.3
debian
около 3 лет назад

Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, fr ...

CVSS3: 7.5
github
около 3 лет назад

ReDoS Vulnerability in ua-parser-js version

EPSS

Процентиль: 81%
0.01515
Низкий

7.5 High

CVSS3