VDB
Sign up
HIGH7.5

GHSA-ffmh-x56j-9rc3

jquery-validation Regular Expression Denial of Service due to arbitrary input to url2 method

Quick fix

GHSA-ffmh-x56j-9rc3 — jquery-validation: upgrade to the fixed version with the command below.

npm install jquery-validation@1.19.5

Details

Summary

Incomplete fix of CVE-2021-43306: An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the jquery-validation npm package, when an attacker is able to supply arbitrary input to the url2 method.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/jquery-validation
Introduced in: 0Fixed in: 1.19.5
Fixnpm install jquery-validation@1.19.5

References