CVE-2022-25927 is a Regular Expression Denial of Service (ReDoS) vulnerability affecting versions of the ua-parser-js package from 0.7.30 up to 0.7.32, and from 0.8.1 up to 1.0.32, specifically within its trim() function. This vulnerability carries a high CVSS score of 7.5, indicating a severe impact on availability due to its network-based attack vector and low attack complexity. While there is no evidence of active exploitation or publicly available exploit code, the vulnerability has garnered some community discussion and media coverage, including a mention in a SecurityWeek article regarding Atlassian patches.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.7.30, < 0.7.33CPE matchmatch criteria | cpe:2.3:a:ua-parser-js_project:ua-parser-js:*:*:*:*:*:node.js:*:* | ||
>= 0.8.1, < 1.0.33CPE matchmatch criteria | cpe:2.3:a:ua-parser-js_project:ua-parser-js:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
ReDoS Vulnerability in ua-parser-js version
Jan 24, 2023ua-parser-js: ReDoS vulnerability via the trim() function
Jan 22, 2023Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regular Expression Denial of Service (ReDoS) via the trim() function.
Jan 10, 2023