Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jxwx-85vp-gvwm

Опубликовано: 13 янв. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Regular Expression Denial of Service in jquery-validation

The GitHub Security Lab team has identified potential security vulnerabilities in jquery.validation.

The project contains one or more regular expressions that are vulnerable to ReDoS (Regular Expression Denial of Service)

This issue was discovered and reported by GitHub team member @erik-krogh (Erik Krogh Kristensen).

Пакеты

Наименование

jquery-validation

npm
Затронутые версииВерсия исправления

< 1.19.3

1.19.3

Наименование

jQuery.Validation

nuget
Затронутые версииВерсия исправления

< 1.19.3

1.19.3

EPSS

Процентиль: 49%
0.00259
Низкий

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 5 лет назад

The jQuery Validation Plugin provides drop-in validation for your existing forms. It is published as an npm package "jquery-validation". jquery-validation before version 1.19.3 contains one or more regular expressions that are vulnerable to ReDoS (Regular Expression Denial of Service). This is fixed in 1.19.3.

CVSS3: 7.5
redhat
около 5 лет назад

The jQuery Validation Plugin provides drop-in validation for your existing forms. It is published as an npm package "jquery-validation". jquery-validation before version 1.19.3 contains one or more regular expressions that are vulnerable to ReDoS (Regular Expression Denial of Service). This is fixed in 1.19.3.

CVSS3: 5.3
nvd
около 5 лет назад

The jQuery Validation Plugin provides drop-in validation for your existing forms. It is published as an npm package "jquery-validation". jquery-validation before version 1.19.3 contains one or more regular expressions that are vulnerable to ReDoS (Regular Expression Denial of Service). This is fixed in 1.19.3.

CVSS3: 5.3
debian
около 5 лет назад

The jQuery Validation Plugin provides drop-in validation for your exis ...

EPSS

Процентиль: 49%
0.00259
Низкий

7.5 High

CVSS3

Дефекты

CWE-400