Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ffmh-x56j-9rc3

Опубликовано: 05 июл. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

jquery-validation Regular Expression Denial of Service due to arbitrary input to url2 method

Summary

Incomplete fix of CVE-2021-43306: An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the jquery-validation npm package, when an attacker is able to supply arbitrary input to the url2 method.

Пакеты

Наименование

jquery-validation

npm
Затронутые версииВерсия исправления

< 1.19.5

1.19.5

EPSS

Процентиль: 63%
0.00438
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

The jQuery Validation Plugin (jquery-validation) provides drop-in validation for forms. Versions of jquery-validation prior to 1.19.5 are vulnerable to regular expression denial of service (ReDoS) when an attacker is able to supply arbitrary input to the url2 method. This is due to an incomplete fix for CVE-2021-43306. Users should upgrade to version 1.19.5 to receive a patch.

CVSS3: 7.5
nvd
больше 3 лет назад

The jQuery Validation Plugin (jquery-validation) provides drop-in validation for forms. Versions of jquery-validation prior to 1.19.5 are vulnerable to regular expression denial of service (ReDoS) when an attacker is able to supply arbitrary input to the url2 method. This is due to an incomplete fix for CVE-2021-43306. Users should upgrade to version 1.19.5 to receive a patch.

CVSS3: 7.5
debian
больше 3 лет назад

The jQuery Validation Plugin (jquery-validation) provides drop-in vali ...

CVSS3: 7.5
fstec
больше 3 лет назад

Уязвимость метода url2 плагина проверки форм jQuery Validation Plugin (jquery-validation), позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 63%
0.00438
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333