A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0. It has been rated as critical. This issue affects the crypto mining component which introduces a backdoor. Upgrading to version 0.7.30, 0.8.1 and 1.0.1 is able to address this issue. It is recommended to upgrade the affected component.
2022-05-24T16:15:07.680
2024-11-21T06:37:11.567
Modified
CVSSv3.1: 5.0 (MEDIUM)
AV:N/AC:H/Au:N/C:C/I:C/A:C
4.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ua-parser-js_project | ua-parser-js | 0.7.29 | Yes |
Application | ua-parser-js_project | ua-parser-js | 0.8.0 | Yes |
Application | ua-parser-js_project | ua-parser-js | 1.0.0 | Yes |