Vulnerability Details CVE-2017-16030
Useragent is used to parse useragent headers. It uses several regular expressions to accomplish this. An attacker could edit their own headers, creating an arbitrarily long useragent string, causing the event loop and server to block. This affects Useragent 2.1.12 and earlier.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 55.1%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2017-16030
-
cpe:2.3:a:useragent_project:useragent:0.1.0
-
cpe:2.3:a:useragent_project:useragent:0.1.1
-
cpe:2.3:a:useragent_project:useragent:0.1.2
-
cpe:2.3:a:useragent_project:useragent:1.0.0
-
cpe:2.3:a:useragent_project:useragent:1.0.1
-
cpe:2.3:a:useragent_project:useragent:1.0.2
-
cpe:2.3:a:useragent_project:useragent:1.0.3
-
cpe:2.3:a:useragent_project:useragent:1.0.4
-
cpe:2.3:a:useragent_project:useragent:1.0.5
-
cpe:2.3:a:useragent_project:useragent:1.0.6
-
cpe:2.3:a:useragent_project:useragent:1.1.0
-
cpe:2.3:a:useragent_project:useragent:2.0.0
-
cpe:2.3:a:useragent_project:useragent:2.0.1
-
cpe:2.3:a:useragent_project:useragent:2.0.10
-
cpe:2.3:a:useragent_project:useragent:2.0.2
-
cpe:2.3:a:useragent_project:useragent:2.0.3
-
cpe:2.3:a:useragent_project:useragent:2.0.4
-
cpe:2.3:a:useragent_project:useragent:2.0.5
-
cpe:2.3:a:useragent_project:useragent:2.0.6
-
cpe:2.3:a:useragent_project:useragent:2.0.7
-
cpe:2.3:a:useragent_project:useragent:2.0.8
-
cpe:2.3:a:useragent_project:useragent:2.0.9
-
cpe:2.3:a:useragent_project:useragent:2.1.0
-
cpe:2.3:a:useragent_project:useragent:2.1.1
-
cpe:2.3:a:useragent_project:useragent:2.1.10
-
cpe:2.3:a:useragent_project:useragent:2.1.11
-
cpe:2.3:a:useragent_project:useragent:2.1.12
-
cpe:2.3:a:useragent_project:useragent:2.1.2
-
cpe:2.3:a:useragent_project:useragent:2.1.3
-
cpe:2.3:a:useragent_project:useragent:2.1.4
-
cpe:2.3:a:useragent_project:useragent:2.1.5
-
cpe:2.3:a:useragent_project:useragent:2.1.6
-
cpe:2.3:a:useragent_project:useragent:2.1.7
-
cpe:2.3:a:useragent_project:useragent:2.1.8
-
cpe:2.3:a:useragent_project:useragent:2.1.9