Validate.js provides a declarative way of validating javascript objects. Versions 0.13.1 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available.
Metrics
Affected Vendors & Products
References
History
Mon, 28 Oct 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ansman
Ansman validate.js |
|
CPEs | cpe:2.3:a:ansman:validate.js:*:*:*:*:*:*:*:* | |
Vendors & Products |
Ansman
Ansman validate.js |
|
Metrics |
ssvc
|
Sat, 26 Oct 2024 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Validate.js provides a declarative way of validating javascript objects. Versions 0.13.1 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available. | |
Title | GHSL-2020-302: Regular Expression Denial of Service (ReDoS) in validate.js | |
Weaknesses | CWE-1333 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-28T14:45:43.110Z
Reserved: 2020-10-01T00:00:00.000Z
Link: CVE-2020-26308

Updated: 2024-10-28T14:45:39.227Z

Status : Awaiting Analysis
Published: 2024-10-26T21:15:14.087
Modified: 2024-10-28T13:58:09.230
Link: CVE-2020-26308

No data.