Junglewise Threat Intelligence

CVE-2020-5243: uap-core ReDoS in User-Agent parsing

CVE-2020-5243 · Severity: low · CVSS 3.1 · Published 2020-02-20

Technologies: uap-core (npm). Vendors: RubyGems, npm.

Executive brief

uap-core is a library that parses User-Agent strings to identify devices and browsers. This vulnerability allows an attacker to send a maliciously crafted User-Agent header in HTTP requests that triggers catastrophic backtracking in the parser's regular expressions, causing the server to consume excessive CPU and become unresponsive. This can lead to denial of service affecting all users of the service.

Technical details

Multiple regular expressions in uap-core contain overlapping capture groups that are vulnerable to regular expression denial of service (ReDoS). The affected regexes parse User-Agent strings for SmartWatch devices, Huawei devices, and HbbTV clients. The backtracking complexity is approximately cubic with respect to input length. An attacker can craft User-Agent strings (e.g., "SmartWatch(" followed by thousands of spaces and a trailing character) that trigger catastrophic backtracking, consuming CPU resources. The vulnerability is exploitable without authentication via HTTP User-Agent headers, which are commonly accepted from untrusted sources. Patches are available in uap-core v0.7.3 and uap-ruby v2.6.0.

Affected products

  • ua-parser uap-core <0.7.3
  • ua-parser uap-ruby <2.6.0

Timeline

  • 2020-02-20: disclosed
  • 2020-02-20: patched: uap-core v0.7.3 released

References

Related threats