CVE-2022-31147: jquery-validation ReDoS in url2 due to incomplete fix of CVE-2021-43306
The jQuery Validation Plugin (jquery-validation) provides drop-in validation for forms. Versions of jquery-validation prior to 1.19.5 are vulnerable to regular expression denial of service (ReDoS) when an attacker is able to supply arbitrary input to the url2 method. This is due to an incomplete fix for CVE-2021-43306. Users should upgrade to version 1.19.5 to receive a patch.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-31147?
CVE-2022-31147 is a vulnerability in the jQuery Validation Plugin (jquery-validation) that allows for regular expression denial of service (ReDoS) when arbitrary input is supplied to the url2 method.
What is the severity of CVE-2022-31147?
CVE-2022-31147 has a severity rating of 7.5 (High).
How does CVE-2022-31147 affect the software?
CVE-2022-31147 affects versions of jquery-validation prior to 1.19.5, specifically the Jqueryvalidation Jquery Validation library.
How can I fix CVE-2022-31147?
To fix CVE-2022-31147, upgrade to version 1.19.5 or later of the jquery-validation library.
Where can I find more information about CVE-2022-31147?
You can find more information about CVE-2022-31147 on the GitHub page for the jquery-validation library, including the commit and release that address the vulnerability, as well as the security advisory.