CVE-2021-43306
Description
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the jquery-validation npm package, when an attacker is able to supply arbitrary input to the url2 method
CWE
- CWE-1333 — CWE-1333 Inefficient Regular Expression Complexity
Affected
- jquery-validation / jquery-validation — v=unspecified <1.19.4 [affected]
CVSS
- 3.1 score=5.9 severity=MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
References
Source
cvelistV5-main/cves/2021/43xxx/CVE-2021-43306.json