CVE-2020-7793 PUBLISHED

The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info).

EPSS 2.64% · 85.6th percentile

Risk Scores

EPSS Score
2.64%
85.6th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSnode-ua-parser-js0, 0.7.14-1
Ubuntu:18.04:LTSnode-ua-parser-js0, 0.7.14-1

Timeline

References

Open in Interactive Console →