Description
Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regular Expression Denial of Service (ReDoS) via the trim() function.
Remediation
References
Related Vulnerabilities
WordPress Plugin Tigris for Salesforce PHP Object Injection (1.1.3)
Undertow Uncontrolled Resource Consumption Vulnerability (CVE-2019-19343)
WordPress Plugin Ninja Forms with File Uploads Extension Cross-Site Scripting (3.3.12)
WordPress Plugin Automated Content for Real Estate Multiple Unspecified Vulnerabilities (5.4.2)