CVE-2021-43306: Regular expression denial of service in jquery-validation
(updated )
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the jquery-validation npm package, when an attacker is able to supply arbitrary input to the url2 method
References
- github.com/advisories/GHSA-j9m2-h2pv-wvph
- github.com/jquery-validation/jquery-validation
- github.com/jquery-validation/jquery-validation/commit/69cb17ed774b427f7e2ffcdf197968231725c30e
- github.com/jquery-validation/jquery-validation/pull/2428
- nvd.nist.gov/vuln/detail/CVE-2021-43306
- research.jfrog.com/vulnerabilities/jquery-validation-redos-xray-211348
Detect and mitigate CVE-2021-43306 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →