7.5

CVE-2021-3794

Exploit

Inefficient Regular Expression Complexity in vuelidate/vuelidate

vuelidate is vulnerable to Inefficient Regular Expression Complexity
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Vuelidate ProjectVuelidate Version < 0.7.7
Vuelidate ProjectVuelidate Version1.0.0 Updatealpha1 SwPlatformnode.js
Vuelidate ProjectVuelidate Version1.0.0 Updatealpha2 SwPlatformnode.js
Vuelidate ProjectVuelidate Version2.0.0 Updatealpha0 SwPlatformnode.js
Vuelidate ProjectVuelidate Version2.0.0 Updatealpha1 SwPlatformnode.js
Vuelidate ProjectVuelidate Version2.0.0 Updatealpha10 SwPlatformnode.js
Vuelidate ProjectVuelidate Version2.0.0 Updatealpha11 SwPlatformnode.js
Vuelidate ProjectVuelidate Version2.0.0 Updatealpha12 SwPlatformnode.js
Vuelidate ProjectVuelidate Version2.0.0 Updatealpha13 SwPlatformnode.js
Vuelidate ProjectVuelidate Version2.0.0 Updatealpha14 SwPlatformnode.js
Vuelidate ProjectVuelidate Version2.0.0 Updatealpha15 SwPlatformnode.js
Vuelidate ProjectVuelidate Version2.0.0 Updatealpha16 SwPlatformnode.js
Vuelidate ProjectVuelidate Version2.0.0 Updatealpha17 SwPlatformnode.js
Vuelidate ProjectVuelidate Version2.0.0 Updatealpha18 SwPlatformnode.js
Vuelidate ProjectVuelidate Version2.0.0 Updatealpha19 SwPlatformnode.js
Vuelidate ProjectVuelidate Version2.0.0 Updatealpha2 SwPlatformnode.js
Vuelidate ProjectVuelidate Version2.0.0 Updatealpha20 SwPlatformnode.js
Vuelidate ProjectVuelidate Version2.0.0 Updatealpha21 SwPlatformnode.js
Vuelidate ProjectVuelidate Version2.0.0 Updatealpha22 SwPlatformnode.js
Vuelidate ProjectVuelidate Version2.0.0 Updatealpha23 SwPlatformnode.js
Vuelidate ProjectVuelidate Version2.0.0 Updatealpha24 SwPlatformnode.js
Vuelidate ProjectVuelidate Version2.0.0 Updatealpha25 SwPlatformnode.js
Vuelidate ProjectVuelidate Version2.0.0 Updatealpha3 SwPlatformnode.js
Vuelidate ProjectVuelidate Version2.0.0 Updatealpha5 SwPlatformnode.js
Vuelidate ProjectVuelidate Version2.0.0 Updatealpha6 SwPlatformnode.js
Vuelidate ProjectVuelidate Version2.0.0 Updatealpha7 SwPlatformnode.js
Vuelidate ProjectVuelidate Version2.0.0 Updatealpha8 SwPlatformnode.js
Vuelidate ProjectVuelidate Version2.0.0 Updatealpha9 SwPlatformnode.js
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.18% 0.637
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
security@huntr.dev 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-1333 Inefficient Regular Expression Complexity

The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.

https://github.com/vuelidate/vuelidate/commit/1f0ca31c30e5032f00dbd14c4791b5ee7928f71d
Patch
Third Party Advisory
https://huntr.dev/bounties/d8201b98-fb91-4c12-a6f7-181b4a20d9b7
Patch
Third Party Advisory
Exploit
Issue Tracking