This repository has been archived by the owner on Jul 30, 2024. It is now read-only.
-
-
Notifications
You must be signed in to change notification settings - Fork 3
fix(deps): update dependency ua-parser-js to v0.7.33 [security] #3
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This pull request is being automatically deployed with Vercel (learn more). 🔍 Inspect: https://vercel.com/innei/candy/ujkRiTzMqffKQxQ1rgXst9XKCMup |
renovate
bot
force-pushed
the
renovate/npm-ua-parser-js-vulnerability
branch
from
June 23, 2022 18:59
b27e7b2
to
4ef71d6
Compare
The latest updates on your projects. Learn more about Vercel for Git ↗︎
|
renovate
bot
changed the title
fix(deps): update dependency ua-parser-js to v0.7.24 [security]
fix(deps): update dependency ua-parser-js to v0.7.24 [SECURITY]
Jun 27, 2022
renovate
bot
changed the title
fix(deps): update dependency ua-parser-js to v0.7.24 [SECURITY]
fix(deps): update dependency ua-parser-js to v0.7.24 [security]
Jun 28, 2022
renovate
bot
changed the title
fix(deps): update dependency ua-parser-js to v0.7.24 [security]
fix(deps): update dependency ua-parser-js to v0.7.33 [security]
Mar 18, 2023
renovate
bot
force-pushed
the
renovate/npm-ua-parser-js-vulnerability
branch
from
March 18, 2023 06:00
4ef71d6
to
eb50707
Compare
renovate
bot
force-pushed
the
renovate/npm-ua-parser-js-vulnerability
branch
from
May 1, 2023 12:21
eb50707
to
01171c3
Compare
renovate
bot
force-pushed
the
renovate/npm-ua-parser-js-vulnerability
branch
from
May 2, 2023 11:02
01171c3
to
6ed3bda
Compare
renovate
bot
force-pushed
the
renovate/npm-ua-parser-js-vulnerability
branch
from
May 6, 2023 09:18
6ed3bda
to
35ee661
Compare
renovate
bot
force-pushed
the
renovate/npm-ua-parser-js-vulnerability
branch
from
May 7, 2023 14:03
35ee661
to
c24b22a
Compare
renovate
bot
force-pushed
the
renovate/npm-ua-parser-js-vulnerability
branch
from
May 9, 2023 06:17
c24b22a
to
ed96d00
Compare
renovate
bot
force-pushed
the
renovate/npm-ua-parser-js-vulnerability
branch
from
May 10, 2023 06:40
ed96d00
to
7b8886f
Compare
renovate
bot
force-pushed
the
renovate/npm-ua-parser-js-vulnerability
branch
from
May 13, 2023 14:06
7b8886f
to
ba02b06
Compare
renovate
bot
force-pushed
the
renovate/npm-ua-parser-js-vulnerability
branch
from
May 16, 2023 03:31
ba02b06
to
85ae69b
Compare
renovate
bot
force-pushed
the
renovate/npm-ua-parser-js-vulnerability
branch
from
May 22, 2023 08:15
85ae69b
to
38b4b05
Compare
renovate
bot
force-pushed
the
renovate/npm-ua-parser-js-vulnerability
branch
from
June 3, 2023 03:23
38b4b05
to
0489d61
Compare
renovate
bot
changed the title
fix(deps): update dependency ua-parser-js to v0.7.33 [security]
fix(deps): update dependency ua-parser-js to v0.7.33 [security] - autoclosed
Feb 15, 2024
renovate
bot
changed the title
fix(deps): update dependency ua-parser-js to v0.7.33 [security] - autoclosed
fix(deps): update dependency ua-parser-js to v0.7.33 [security]
Feb 15, 2024
renovate
bot
force-pushed
the
renovate/npm-ua-parser-js-vulnerability
branch
from
February 15, 2024 17:06
0489d61
to
282754b
Compare
renovate
bot
changed the title
fix(deps): update dependency ua-parser-js to v0.7.33 [security]
fix(deps): update dependency ua-parser-js to v0.7.33 [security] - autoclosed
Feb 24, 2024
renovate
bot
changed the title
fix(deps): update dependency ua-parser-js to v0.7.33 [security] - autoclosed
fix(deps): update dependency ua-parser-js to v0.7.33 [security]
Feb 24, 2024
renovate
bot
force-pushed
the
renovate/npm-ua-parser-js-vulnerability
branch
from
February 24, 2024 09:14
282754b
to
bbfcec8
Compare
renovate
bot
force-pushed
the
renovate/npm-ua-parser-js-vulnerability
branch
from
July 17, 2024 07:18
bbfcec8
to
09e3811
Compare
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Labels
None yet
0 participants
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.7.21
->0.7.33
GitHub Vulnerability Alerts
CVE-2021-27292
ua-parser-js >= 0.7.14, fixed in 0.7.24, uses a regular expression which is vulnerable to denial of service. If an attacker sends a malicious User-Agent header, ua-parser-js will get stuck processing it for an extended period of time.
CVE-2020-7733
The package ua-parser-js before 0.7.22 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex for Redmi Phones and Mi Pad Tablets UA.
CVE-2020-7793
The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info).
CVE-2022-25927
Description:
A regular expression denial of service (ReDoS) vulnerability has been discovered in
ua-parser-js
.Impact:
This vulnerability bypass the library's
MAX_LENGTH
input limit prevention. By crafting a very-very-long user-agent string with specific pattern, an attacker can turn the script to get stuck processing for a very long time which results in a denial of service (DoS) condition.Affected Versions:
All versions of the library prior to version
0.7.33
/1.0.33
.Patches:
A patch has been released to remove the vulnerable regular expression, update to version
0.7.33
/1.0.33
or later.References:
Regular expression Denial of Service - ReDoS
Credits:
Thanks to @Snyk who first reported the issue.
Release Notes
faisalman/ua-parser-js (ua-parser-js)
v0.7.33
Compare Source
v0.7.32
Compare Source
v0.7.31
Compare Source
v0.7.30
Compare Source
v0.7.28
Compare Source
v0.7.27
Compare Source
v0.7.26
Compare Source
v0.7.25
Compare Source
v0.7.24
Compare Source
v0.7.23
Compare Source
v0.7.22
Compare Source
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.