Junglewise Threat Intelligence

CVE-2021-21252: jquery-validation regular expression denial of service

CVE-2021-21252 · Severity: low · CVSS 3.1 · Published 2021-01-13

Technologies: Jquery-Validation. Vendors: npm.

Executive brief

jQuery Validation is a widely-used client-side form validation library integrated into many websites and web applications. An attacker can craft malicious input that triggers catastrophic backtracking in the library's regular expressions, causing the application to become unresponsive or crash. This can lead to denial of service against users attempting to validate forms, disrupting normal application usage.

Technical details

The vulnerability is a Regular Expression Denial of Service (ReDoS) affecting one or more regex patterns in jquery-validation. An attacker can supply crafted input that causes regex engines to experience catastrophic backtracking, leading to CPU exhaustion and application hang. The attack vector is network-based with no authentication or user interaction required beyond normal form submission. By submitting malicious data to a form protected by vulnerable validation rules, an attacker can trigger the DoS condition. The vulnerability was fixed in version 1.19.3; users should upgrade immediately.

Affected products

  • jquery-validation jquery-validation before 1.19.3

Timeline

  • 2021-01-13: disclosed
  • 2021-01-13: patched: Version 1.19.3 released

References

Related threats