Vulnerability Description
The jQuery Validation Plugin provides drop-in validation for your existing forms. It is published as an npm package "jquery-validation". jquery-validation before version 1.19.3 contains one or more regular expressions that are vulnerable to ReDoS (Regular Expression Denial of Service). This is fixed in 1.19.3.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jqueryvalidation | Jquery Validation | < 1.19.3 |
| Netapp | Snapcenter | - |
Related Weaknesses (CWE)
References
- https://github.com/jquery-validation/jquery-validation/commit/5d8f29eef363d043a8PatchThird Party Advisory
- https://github.com/jquery-validation/jquery-validation/pull/2371PatchThird Party Advisory
- https://github.com/jquery-validation/jquery-validation/security/advisories/GHSA-Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html
- https://security.netapp.com/advisory/ntap-20210219-0005/Third Party Advisory
- https://www.npmjs.com/package/jquery-validationProductThird Party Advisory
- https://github.com/jquery-validation/jquery-validation/commit/5d8f29eef363d043a8PatchThird Party Advisory
- https://github.com/jquery-validation/jquery-validation/pull/2371PatchThird Party Advisory
- https://github.com/jquery-validation/jquery-validation/security/advisories/GHSA-Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html
- https://security.netapp.com/advisory/ntap-20210219-0005/Third Party Advisory
- https://www.npmjs.com/package/jquery-validationProductThird Party Advisory
FAQ
What is CVE-2021-21252?
CVE-2021-21252 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The jQuery Validation Plugin provides drop-in validation for your existing forms. It is published as an npm package "jquery-validation". jquery-validation before version 1.19.3 contains one or more re...
How severe is CVE-2021-21252?
CVE-2021-21252 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-21252?
Check the references section above for vendor advisories and patch information. Affected products include: Jqueryvalidation Jquery Validation, Netapp Snapcenter.