GHSA-c4pm-63cg-9j7h
Dashboard / Vulnerabilities / GHSA-c4pm-63cg-9j7h
Summary: Yauaa vulnerable to ArrayIndexOutOfBoundsException triggered by a crafted Sec-Ch-Ua-Full-Version-List
Details: ### Impact Applications using the Client Hints analysis feature introduced with 7.0.0 can crash because the Yauaa library throws an ArrayIndexOutOfBoundsException. Applications that do not use this feature are not affected. ### Patches Upgrade to 7.9.0 ### Workarounds Catch and discard any exceptions from Yauaa.
References: https://github.com/nielsbasjes/yauaa/security/advisories/GHSA-c4pm-63cg-9j7h, https://nvd.nist.gov/vuln/detail/CVE-2022-23496, https://github.com/nielsbasjes/yauaa/commit/3017a866e2cff0d308f264b66fde4fa79e3beb9e, https://github.com/nielsbasjes/yauaa
Affected packages
Package
Name: nl.basjes.parse.useragent:yauaa
Purl: pkg:maven/nl.basjes.parse.useragent/yauaa
Affected ranges
Type: ECOSYSTEM
Events:
