Lucene search

K
osvGoogleOSV:CVE-2021-27292
HistoryMar 17, 2021 - 1:15 p.m.

CVE-2021-27292

2021-03-1713:15:15
Google
osv.dev
15

6.5 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

64.6%

ua-parser-js >= 0.7.14, fixed in 0.7.24, uses a regular expression which is vulnerable to denial of service. If an attacker sends a malicious User-Agent header, ua-parser-js will get stuck processing it for an extended period of time.

6.5 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

64.6%