Description
This affects the package es6-crawler-detect before 3.1.3. No limitation of user agent string length supplied to regex operators.
Remediation
References
https://snyk.io/vuln/SNYK-JS-ES6CRAWLERDETECT-1051529
https://github.com/JefferyHus/es6-crawler-detect/pull/27
Related Vulnerabilities
CVE-2022-43183 Vulnerability in maven package com.xuxueli:xxl-job
CVE-2017-16036 Vulnerability in npm package badjs-sourcemap-server
CVE-2020-36376 Vulnerability in npm package aaptjs
CVE-2023-51079 Vulnerability in maven package org.mvel:mvel2
CVE-2023-33202 Vulnerability in maven package org.bouncycastle:bcprov-jdk15on