Executive brief
ua-parser-js is a popular JavaScript library used to identify browser, engine, OS, and device details from user-agent strings. A vulnerability in how it processes these strings allows an attacker to send a specially crafted request that causes the system to consume excessive CPU resources. This can lead to a service slowdown or a complete crash, preventing legitimate users from accessing the application.
Technical details
The ua-parser-js library before version 0.7.23 contains multiple regular expressions susceptible to catastrophic backtracking. An attacker can exploit this by providing a malicious User-Agent string (e.g., containing long sequences of specific characters) that triggers exponential processing time in the regex engine. This is a Regular Expression Denial of Service (ReDoS) vulnerability (CWE-400). The attack can be executed remotely without authentication or user interaction. Successful exploitation results in high CPU exhaustion, leading to a Denial of Service (DoS) condition. The issue is fixed in version 0.7.23 by optimizing the affected regex patterns.
Affected products
- faisalman ua-parser-js < 0.7.23
Timeline
- 2020-10-29: disclosed: Vulnerability disclosed to maintainer
- 2020-12-01: patched: Fix committed to repository
- 2020-12-11: advisory: NVD published CVE-2020-7793
References
- https://github.com/faisalman/ua-parser-js/commit/6d1f26df051ba681463ef109d36c9cf0f7e32b18
- https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBFAISALMAN-1050388
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1050387
- https://snyk.io/vuln/SNYK-JS-UAPARSERJS-1023599