Asymmetric denial of service - ReDoS In jquery-validation
Description
jquery-validation Regular Expression Denial of Service due to arbitrary input to url2 method Summary
Incomplete fix of CVE-2021-43306: An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the jquery-validation npm package, when an attacker is able to supply arbitrary input to the url2 method.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
npm | 1.19.5 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3. 4.