Lucene search

K
cvelistGitHub_MCVELIST:CVE-2021-21252
HistoryJan 13, 2021 - 12:00 a.m.

CVE-2021-21252 Regular expression denial of service in jquery-validation

2021-01-1300:00:00
CWE-400
GitHub_M
www.cve.org
6
jquery validation plugin
redos
regular expression denial of service

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AI Score

7.7

Confidence

High

EPSS

0.004

Percentile

72.0%

The jQuery Validation Plugin provides drop-in validation for your existing forms. It is published as an npm package “jquery-validation”. jquery-validation before version 1.19.3 contains one or more regular expressions that are vulnerable to ReDoS (Regular Expression Denial of Service). This is fixed in 1.19.3.

CNA Affected

[
  {
    "vendor": "jquery-validation",
    "product": "jquery-validation",
    "versions": [
      {
        "version": "< 1.19.3",
        "status": "affected"
      }
    ]
  }
]

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AI Score

7.7

Confidence

High

EPSS

0.004

Percentile

72.0%