CVE-2020-7793

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/12/2020
Last modified:
13/09/2022

Description

The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ua-parser-js_project:ua-parser-js:*:*:*:*:*:node.js:*:* 0.7.23 (excluding)
cpe:2.3:a:siemens:sinec_ins:*:*:*:*:*:*:*:* 1.0 (excluding)
cpe:2.3:a:siemens:sinec_ins:1.0:-:*:*:*:*:*:*
cpe:2.3:a:siemens:sinec_ins:1.0:sp1:*:*:*:*:*:*