You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Vulnerability Description: The vulnerabilities in ua-parser-js arise due to outdated inner dependencies, which have not been updated for over 7 years. Even though some dependencies used within the package may have been updated, the lack of updates to the main package opens it up to potential risks, including Regular Expression Denial of Service (ReDoS) attacks.
Vulnerability Description: The vulnerabilities in ua-parser-js arise due to outdated inner dependencies, which have not been updated for over 7 years. Even though some dependencies used within the package may have been updated, the lack of updates to the main package opens it up to potential risks, including Regular Expression Denial of Service (ReDoS) attacks.
Vulnerabilities Found in ua-parser-js Package (CVE-2020-7733, CVE-2020-7793, CVE-2022-25927)
Vulnerability Details:
Vulnerability IDs: CVE-2020-7733 (NVD), CVE-2020-7793 (NVD), CVE-2022-25927 (NVD)
Highest Severity: HIGH
CVE Count: 3
Confidence: HIGHEST
Evidence Count: 3
Identifiers: pkg:javascript/[email protected]
CVSS Scores and Vectors:
Base Score: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWEs: CWE-400, NVD-CWE-Other, CWE-1333
Request for Action:
The text was updated successfully, but these errors were encountered: