Description
This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The vulnerable regular expression is located in https://github.com/codemirror/CodeMirror/blob/cdb228ac736369c685865b122b736cd0d397836c/mode/javascript/javascript.jsL129.
Recommendation
Update the codemirror package to the latest compatible version. Followings are version details:
- Affected version(s): < 5.58.2
- Patched version(s): 5.58.2
References
Could your website be exposed too?
SmartScanner can check your website for Regular expression denial of service in codemirror and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Regular Expression Denial of Service (ReDoS) in lodash - CVE-2020-28500
- Knwl.js Regular Expression Denial of Service vulnerability - CVE-2020-26306
- Regular Expression Denial of Service in papaparse - CVE-2020-36649
- CommonRegexJS Regular Expression Denial of Service vulnerability - CVE-2020-26305


