nodejs-useragent before version 2.1.13 is vulnerable to regular expression denial of service when an arbitrarily long User-Agent header is parsed. Reference: https://nodesecurity.io/advisories/312# Upstream Patches: https://github.com/3rd-Eden/useragent/commit/cbc106584bc417bd5843d3e0fa4d89ef81cd6988 https://github.com/3rd-Eden/useragent/commit/b18cf7c2a13c994ea8d6d0d132feef4eb8193c36
This vulnerability is out of security support scope for the following product: * Red Hat Mobile Application Platform Please refer to https://access.redhat.com/support/policy/updates/rhmap for more details
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2017-16030