Regular expression denial of service (ReDoS) in EmailField component in Vaadin 14 and 15-17
High severity
GitHub Reviewed
Published
Apr 16, 2021
in
vaadin/flow-components
•
Updated Jan 9, 2023
Package
Affected versions
>= 2.0.4, < 2.3.3
>= 3.0.0, < 4.0.3
Patched versions
2.3.3
4.0.3
Description
Reviewed
Apr 16, 2021
Published to the GitHub Advisory Database
Apr 19, 2021
Last updated
Jan 9, 2023
Unsafe validation RegEx in
EmailField
component incom.vaadin:vaadin-text-field-flow
versions 2.0.4 through 2.3.2 (Vaadin 14.0.6 through 14.4.3), and 3.0.0 through 4.0.2 (Vaadin 15.0.0 through 17.0.10) allows attackers to cause uncontrolled resource consumption by submitting malicious email addresses.References