PT-2024-10800 · Unknown · Validate.Js

Erik Krogh Kristensen

·

Published

2024-10-26

·

Updated

2024-10-28

·

CVE-2020-26310

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/U:Green
Name of the Vulnerable Software and Affected Versions Validate.js versions prior to the version released after 30 November 2020
Description The issue concerns Regular Expression Denial of Service (ReDoS) due to vulnerable regular expressions in Validate.js. As of the time of publication, it is unknown if any patches are available.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Weakness Enumeration

Related Identifiers

CVE-2020-26310

Affected Products

Validate.Js