Regular expression denial of service in jquery-validation
Vulnerability Description
The jQuery Validation Plugin provides drop-in validation for your existing forms. It is published as an npm package "jquery-validation". jquery-validation before version 1.19.3 contains one or more regular expressions that are vulnerable to ReDoS (Regular Expression Denial of Service). This is fixed in 1.19.3.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-21252
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/jquery-validation/jquery-validation/security/advisories/GHSA-jxwx-85vp-gvwm
- https://github.com/jquery-validation/jquery-validation/pull/2371
- https://github.com/jquery-validation/jquery-validation/commit/5d8f29eef363d043a8fec4eb86d42cadb5fa5f7d
- https://www.npmjs.com/package/jquery-validation
- https://security.netapp.com/advisory/ntap-20210219-0005/
- https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html
Affected Vendor
jquery-validation
View all reports →