Логотип exploitDog
bind:CVE-2020-5243
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-5243

Количество 4

Количество 4

ubuntu логотип

CVE-2020-5243

почти 6 лет назад

uap-core before 0.7.3 is vulnerable to a denial of service attack when processing crafted User-Agent strings. Some regexes are vulnerable to regular expression denial of service (REDoS) due to overlapping capture groups. This allows remote attackers to overload a server by setting the User-Agent header in an HTTP(S) request to maliciously crafted long strings. This has been patched in uap-core 0.7.3.

CVSS3: 5.7
EPSS: Низкий
nvd логотип

CVE-2020-5243

почти 6 лет назад

uap-core before 0.7.3 is vulnerable to a denial of service attack when processing crafted User-Agent strings. Some regexes are vulnerable to regular expression denial of service (REDoS) due to overlapping capture groups. This allows remote attackers to overload a server by setting the User-Agent header in an HTTP(S) request to maliciously crafted long strings. This has been patched in uap-core 0.7.3.

CVSS3: 5.7
EPSS: Низкий
debian логотип

CVE-2020-5243

почти 6 лет назад

uap-core before 0.7.3 is vulnerable to a denial of service attack when ...

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-cmcx-xhr8-3w9p

почти 6 лет назад

Denial of Service in uap-core when processing crafted User-Agent strings

CVSS3: 5.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-5243

uap-core before 0.7.3 is vulnerable to a denial of service attack when processing crafted User-Agent strings. Some regexes are vulnerable to regular expression denial of service (REDoS) due to overlapping capture groups. This allows remote attackers to overload a server by setting the User-Agent header in an HTTP(S) request to maliciously crafted long strings. This has been patched in uap-core 0.7.3.

CVSS3: 5.7
1%
Низкий
почти 6 лет назад
nvd логотип
CVE-2020-5243

uap-core before 0.7.3 is vulnerable to a denial of service attack when processing crafted User-Agent strings. Some regexes are vulnerable to regular expression denial of service (REDoS) due to overlapping capture groups. This allows remote attackers to overload a server by setting the User-Agent header in an HTTP(S) request to maliciously crafted long strings. This has been patched in uap-core 0.7.3.

CVSS3: 5.7
1%
Низкий
почти 6 лет назад
debian логотип
CVE-2020-5243

uap-core before 0.7.3 is vulnerable to a denial of service attack when ...

CVSS3: 5.7
1%
Низкий
почти 6 лет назад
github логотип
GHSA-cmcx-xhr8-3w9p

Denial of Service in uap-core when processing crafted User-Agent strings

CVSS3: 5.7
1%
Низкий
почти 6 лет назад

Уязвимостей на страницу