CVE-2021-21252

The jQuery Validation Plugin provides drop-in validation for your existing forms. It is published as an npm package "jquery-validation". jquery-validation before version 1.19.3 contains one or more regular expressions that are vulnerable to ReDoS (Regular Expression Denial of Service). This is fixed in 1.19.3.
Severity
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Atk. Vector
NETWORK
Atk. Complexity
LOW
Priv. Required
NONE
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
VendorProductVersion
jqueryvalidationjquery_validation
𝑥
< 1.19.3
netappsnapcenter
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
civicrm
bullseye
no-dsa
stretch
no-dsa
sid
5.68.1+dfsg1-1
fixed
otrs2
bullseye/non-free
6.0.32-6
fixed
stretch
no-dsa
phpmyadmin
bullseye
4:5.0.4+dfsg2-2+deb11u1
no-dsa
stretch
no-dsa
bookworm
4:5.2.1+dfsg-1
fixed
sid
4:5.2.1+dfsg-4
fixed
trixie
4:5.2.1+dfsg-4
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
civicrm
noble
dne
mantic
dne
lunar
dne
kinetic
ignored
jammy
needed
impish
ignored
hirsute
ignored
groovy
ignored
focal
needed
bionic
needed
xenial
needed
trusty
dne
otrs2
noble
dne
mantic
dne
lunar
dne
kinetic
dne
jammy
needed
impish
ignored
hirsute
ignored
groovy
ignored
focal
needed
bionic
needed
xenial
needed
trusty
dne
phpmyadmin
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
not-affected
jammy
not-affected
impish
not-affected
hirsute
not-affected
groovy
ignored
focal
needed
bionic
needed
xenial
needed
trusty
needed