PT-2024-10799 · Unknown+1 · Validate.Js+1

Erik Krogh Kristensen

·

Published

2024-10-26

·

Updated

2024-10-28

·

CVE-2020-26309

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Green
Name of the Vulnerable Software and Affected Versions Validate.js versions 0.11.3 and prior Nope versions 0.11.3 and prior
Description The issue concerns Regular Expression Denial of Service (ReDoS) due to one or more vulnerable regular expressions.
Recommendations For Validate.js versions 0.11.3 and prior: At the moment, there is no information about a newer version that contains a fix for this vulnerability. For Nope versions 0.11.3 and prior: Update to version 0.12.1 to resolve the issue.

DoS

Weakness Enumeration

Related Identifiers

CVE-2020-26309
GHSA-3PHV-83CJ-P8P7

Affected Products

Nope
Validate.Js