Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-21252

Опубликовано: 13 янв. 2021
Источник: debian
EPSS Низкий

Описание

The jQuery Validation Plugin provides drop-in validation for your existing forms. It is published as an npm package "jquery-validation". jquery-validation before version 1.19.3 contains one or more regular expressions that are vulnerable to ReDoS (Regular Expression Denial of Service). This is fixed in 1.19.3.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
civicrmfixed5.50.1+dfsg1-1package
civicrmno-dsabullseyepackage
otrs2fixed6.0.32-4package
otrs2ignoredstretchpackage
phpmyadminfixed4:5.0.4+dfsg2-2package
phpmyadminno-dsastretchpackage
node-jquery-validationnot-affectedpackage

Примечания

  • https://github.com/jquery-validation/jquery-validation/security/advisories/GHSA-jxwx-85vp-gvwm

  • not packaged, but civicrm, otrs2, and phpmyadmin embed a copy

  • https://github.com/phpmyadmin/phpmyadmin/commit/401eedd288c4e83d69287b97a9f574f231156171

EPSS

Процентиль: 66%
0.00504
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 5 лет назад

The jQuery Validation Plugin provides drop-in validation for your existing forms. It is published as an npm package "jquery-validation". jquery-validation before version 1.19.3 contains one or more regular expressions that are vulnerable to ReDoS (Regular Expression Denial of Service). This is fixed in 1.19.3.

CVSS3: 7.5
redhat
около 5 лет назад

The jQuery Validation Plugin provides drop-in validation for your existing forms. It is published as an npm package "jquery-validation". jquery-validation before version 1.19.3 contains one or more regular expressions that are vulnerable to ReDoS (Regular Expression Denial of Service). This is fixed in 1.19.3.

CVSS3: 5.3
nvd
около 5 лет назад

The jQuery Validation Plugin provides drop-in validation for your existing forms. It is published as an npm package "jquery-validation". jquery-validation before version 1.19.3 contains one or more regular expressions that are vulnerable to ReDoS (Regular Expression Denial of Service). This is fixed in 1.19.3.

CVSS3: 7.5
github
около 5 лет назад

Regular Expression Denial of Service in jquery-validation

EPSS

Процентиль: 66%
0.00504
Низкий