CVE-2021-21252: GHSL-2020-294: ReDoS (Regular Expression Denial of Service) in jquery.validation - CVE-2021-21252
The GitHub Security Lab team has identified potential security vulnerabilities in jquery.validation.
The project contains one or more regular expressions that are vulnerable to ReDoS (Regular Expression Denial of Service)
This issue was discovered and reported by GitHub team member @erik-krogh (Erik Krogh Kristensen).
Other sources
The jQuery Validation Plugin provides drop-in validation for your existing forms. It is published as an npm package "jquery-validation". jquery-validation before version 1.19.3 contains one or more regular expressions that are vulnerable to ReDoS (Regular Expression Denial of Service). This is fixed in 1.19.3.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21252?
CVE-2021-21252 has a moderate severity level due to its potential for Regular Expression Denial of Service (ReDoS) attacks.
How do I fix CVE-2021-21252?
To fix CVE-2021-21252, upgrade to jQuery.Validation version 1.19.3 or later.
What software is affected by CVE-2021-21252?
CVE-2021-21252 affects jQuery.Validation versions prior to 1.19.3, as well as related packages in npm and NuGet.
When was CVE-2021-21252 discovered?
CVE-2021-21252 was reported by the GitHub Security Lab team aiming to raise awareness of vulnerabilities in jQuery.Validation.
What type of vulnerability is CVE-2021-21252?
CVE-2021-21252 is a Regular Expression Denial of Service (ReDoS) vulnerability.