Lucene search

K
cvelist@huntrdevCVELIST:CVE-2021-3765
HistoryNov 02, 2021 - 7:05 a.m.

CVE-2021-3765 Inefficient Regular Expression Complexity in validatorjs/validator.js

2021-11-0207:05:10
CWE-1333
@huntrdev
www.cve.org
5
cve-2021-3765
validator.js
inefficient regular expression

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AI Score

8.7

Confidence

High

EPSS

0.001

Percentile

46.0%

validator.js is vulnerable to Inefficient Regular Expression Complexity

CNA Affected

[
  {
    "product": "validatorjs/validator.js",
    "vendor": "validatorjs",
    "versions": [
      {
        "lessThan": "13.7.0",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AI Score

8.7

Confidence

High

EPSS

0.001

Percentile

46.0%