LOW
GHSA-j9m2-h2pv-wvph
Regular expression denial of service in jquery-validation
Quick fix
GHSA-j9m2-h2pv-wvph — jquery-validation: upgrade to the fixed version with the command below.
npm install jquery-validation@1.19.4Details
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the jquery-validation npm package, when an attacker is able to supply arbitrary input to the url2 method
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-43306[ADVISORY]
- https://github.com/jquery-validation/jquery-validation/pull/2428[WEB]
- https://github.com/jquery-validation/jquery-validation/commit/69cb17ed774b427f7e2ffcdf197968231725c30e[WEB]
- https://github.com/jquery-validation/jquery-validation[PACKAGE]
- https://research.jfrog.com/vulnerabilities/jquery-validation-redos-xray-211348[WEB]