GHSA-236c-vhj4-gfxg
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-pjwm-rvh2-c87w. This link is maintained to preserve external references.
Original Description
A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0. It has been rated as critical. This issue affects the crypto mining component which introduces a backdoor. Upgrading to version 0.7.30, 0.8.1 and 1.0.1 is able to address this issue. It is recommended to upgrade the affected component.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2021-4229, https://github.com/faisalman/ua-parser-js/issues/536, https://github.com/advisories/GHSA-pjwm-rvh2-c87w, https://vuldb.com/?id.185453
