VDB
CVE-2021-21252
CVE-2021-21252
PUBLISHED
The jQuery Validation Plugin provides drop-in validation for your existing forms. It is published as an npm package "jquery-validation". jquery-validation before version 1.19.3 contains one or more regular expressions that are vulnerable to ReDoS (Regular Expression Denial of Service). This is fixed in 1.19.3.
EPSS 0.73% · 72.9th percentile
Risk Scores
EPSS Score
0.73%
72.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:22.04:LTS | otrs2 | 6.2.2-2, 0, 6.0.32-6 |
| Ubuntu:Pro:14.04:LTS | phpmyadmin | 4:4.0.10-1ubuntu0.1+esm1, *, 4:4.0.10-1ubuntu0.1+esm4 |
| Ubuntu:Pro:20.04:LTS | phpmyadmin | 4:4.9.1+dfsg1-2, 4:4.9.5+dfsg1-1ubuntu1, 4:4.9.5+dfsg1-2 |
| Ubuntu:18.04:LTS | otrs2 | 6.0.5-1, 6.0.4-1, 6.0.3-1 |
| Ubuntu:16.04:LTS | otrs2 | 5.0.6-1, 5.0.3-1, 5.0.2-1 |
| Ubuntu:18.04:LTS | civicrm | 4.7.30+dfsg-1ubuntu1, 0, 4.7.23+dfsg-1ubuntu1 |
| Ubuntu:20.04:LTS | otrs2 | 6.0.25-1, 6.0.23-2, 0 |
| Ubuntu:16.04:LTS | civicrm | 0, 4.7.1+dfsg-2ubuntu1, 4.7.1+dfsg-2 |
| Ubuntu:20.04:LTS | civicrm | *, 5.18.1+dfsg-1, 5.20.3+dfsg-1 |
| Ubuntu:22.04:LTS | civicrm | 5.33.2+dfsg1-1build1, 5.33.2+dfsg1-1, 0 |
| Ubuntu:Pro:16.04:LTS | phpmyadmin | *, *, * |
| Ubuntu:Pro:18.04:LTS | phpmyadmin | 4:4.6.6-5ubuntu0.2+esm1, 4:4.6.6-5, 0 |
Timeline
- Jan 13, 2021 CVE Published
- Feb 22, 2021 CVE Updated
- Apr 14, 2021 EPSS Score
- Jun 22, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 27, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 2, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
References
- https://ubuntu.com/security/CVE-2021-21252 third-party-advisory
- https://github.com/jquery-validation/jquery-validation/security/advisories/GHSA-jxwx-85vp-gvwm third-party-advisory
- https://github.com/phpmyadmin/phpmyadmin/commit/401eedd288c4e83d69287b97a9f574f231156171 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2021-21252 third-party-advisory