Vulnerability Description
vuelidate is vulnerable to Inefficient Regular Expression Complexity
CVSS Score
7.5
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vuelidate Project | Vuelidate | < 0.7.7 |
Related Weaknesses (CWE)
References
- https://github.com/vuelidate/vuelidate/commit/1f0ca31c30e5032f00dbd14c4791b5ee79PatchThird Party Advisory
- https://huntr.dev/bounties/d8201b98-fb91-4c12-a6f7-181b4a20d9b7ExploitIssue TrackingPatch
- https://github.com/vuelidate/vuelidate/commit/1f0ca31c30e5032f00dbd14c4791b5ee79PatchThird Party Advisory
- https://huntr.dev/bounties/d8201b98-fb91-4c12-a6f7-181b4a20d9b7ExploitIssue TrackingPatch
FAQ
What is CVE-2021-3794?
CVE-2021-3794 is a vulnerability with a CVSS score of 7.5 (HIGH). vuelidate is vulnerable to Inefficient Regular Expression Complexity
How severe is CVE-2021-3794?
CVE-2021-3794 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-3794?
Check the references section above for vendor advisories and patch information. Affected products include: Vuelidate Project Vuelidate.