Описание
Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode variation selectors (\uFE0F, \uFE0E) appearing in a sequence which lead to improper string length calculation. This can lead to an application using isLength for input validation accepting strings significantly longer than intended, resulting in issues like data truncation in databases, buffer overflows in other system components, or denial-of-service.
Ссылки
- ExploitThird Party Advisory
- Issue TrackingPatch
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 13.15.22 (исключая)
cpe:2.3:a:validator_project:validator:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 22%
0.00074
Низкий
7.5 High
CVSS3
Дефекты
CWE-792
CWE-172
Связанные уязвимости
CVSS3: 7.5
github
2 месяца назад
Validator is Vulnerable to Incomplete Filtering of One or More Instances of Special Elements
EPSS
Процентиль: 22%
0.00074
Низкий
7.5 High
CVSS3
Дефекты
CWE-792
CWE-172