GMS-2021-194: Inefficient Regular Expression Complexity in Validator.js
Impact
Versions of validator
prior to 13.7.0 are affected by an inefficient Regular Expression complexity when using the rtrim
and trim
sanitizers.
Patches
The problem has been patched in validator 13.7.0
References
- github.com/advisories/GHSA-xx4c-jj58-r7x6
- github.com/validatorjs/validator.js/issues/1599
- github.com/validatorjs/validator.js/pull/1738
- github.com/validatorjs/validator.js/security/advisories/GHSA-xx4c-jj58-r7x6
- huntr.dev/bounties/c37e975c-21a3-4c5f-9b57-04d63b28cfc9/
- nvd.nist.gov/vuln/detail/CVE-2021-3765
Detect and mitigate GMS-2021-194 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →