HIGH7.5
GHSA-ffmh-x56j-9rc3
jquery-validation Regular Expression Denial of Service due to arbitrary input to url2 method
Quick fix
GHSA-ffmh-x56j-9rc3 — jquery-validation: upgrade to the fixed version with the command below.
npm install jquery-validation@1.19.5Details
Summary
Incomplete fix of CVE-2021-43306: An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the jquery-validation npm package, when an attacker is able to supply arbitrary input to the url2 method.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/jquery-validation/jquery-validation/security/advisories/GHSA-ffmh-x56j-9rc3[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2022-31147[ADVISORY]
- https://github.com/jquery-validation/jquery-validation/commit/5bbd80d27fc6b607d2f7f106c89522051a9fb0dd[WEB]
- https://github.com/jquery-validation/jquery-validation[PACKAGE]
- https://github.com/jquery-validation/jquery-validation/releases/tag/1.19.5[WEB]