Description


It was discovered that the is-my-json-valid JavaScript library used an inefficient regular expression to validate JSON fields defined to have email format. A specially crafted JSON file could cause it to consume an excessive amount of CPU time when validated.

Related CPE's


a

is-my-json-valid_project

is-my-json-valid

2

References


https://bugzilla.redhat.com/show_bug.cgi?id=1546357

Issue TrackingPatchThird Party Advisory

Weaknesses



CWE-400

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

5.3 · Medium

  • CVSS V3.1

  • CVSS V3.0

  • CVSS V2.0

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2021-03-30T02:15:14.593

4 years ago

Last modified

2021-04-02T15:16:52.663

4 years ago