icon

We found results for “

WS-2017-3757

Good to know:

icon
icon

Date: December 10, 2017

all versions prior to 2.0.0 of content-type-parser npm package are vulnerable to ReDoS via the user agent parser. the vulnerability was fixed by reintroducing a new parser and deleting the old one.

Language: Java

Severity Score

Severity Score

Weakness Type (CWE)

Incorrect Regular Expression

CWE-185

Top Fix

icon

Upgrade Version

Upgrade to version oburatongoi/productivity - 0.3.36;oburatongoi/productivity - 0.0.1;oburatongoi/productivity - no_fix;jsdom - 11.11.0;humanmade/workflows - 0.4.8-rc.1;humanmade/workflows - dev-master;content-type-parser - no_fix;org.webjars.npm:content-type-parser:no_fix

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): LOW

Do you need more information?

Contact Us