jquery-validation Regular Expression Denial of Service due to arbitrary input to url2 method
High severity
GitHub Reviewed
Published
Jul 1, 2022
in
jquery-validation/jquery-validation
•
Updated Jan 27, 2023
Description
Published to the GitHub Advisory Database
Jul 5, 2022
Reviewed
Jul 5, 2022
Published by the National Vulnerability Database
Jul 14, 2022
Last updated
Jan 27, 2023
Summary
Incomplete fix of CVE-2021-43306: An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the jquery-validation npm package, when an attacker is able to supply arbitrary input to the url2 method.
References