Medium severity5.0NVD Advisory· Published May 24, 2022· Updated Jun 17, 2026
CVE-2021-4229
CVE-2021-4229
Description
A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0. It has been rated as critical. This issue affects the crypto mining component which introduces a backdoor. Upgrading to version 0.7.30, 0.8.1 and 1.0.1 is able to address this issue. It is recommended to upgrade the affected component.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ua-parser-jsnpm | >= 0.7.29, < 0.7.30 | 0.7.30 |
ua-parser-jsnpm | >= 0.8.0, < 0.8.1 | 0.8.1 |
ua-parser-jsnpm | >= 1.0.0, < 1.0.1 | 1.0.1 |
Affected products
2- unspecified/ua-parser-jsv5Range: 0.7.29
Patches
Vulnerability mechanics
References
5- github.com/faisalman/ua-parser-js/issues/536nvdIssue TrackingPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-pjwm-rvh2-c87wnvdThird Party AdvisoryADVISORY
- vuldb.comnvdThird Party AdvisoryVDB Entry
- github.com/faisalman/ua-parser-js/issues/536ghsaWEB
- www.npmjs.com/package/ua-parser-jsghsaWEB
News mentions
0No linked articles in our index yet.