Description
This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The vulnerable regular expression is located in https://github.com/codemirror/CodeMirror/blob/cdb228ac736369c685865b122b736cd0d397836c/mode/javascript/javascript.jsL129.
Recommendation
Update the codemirror package to the latest compatible version. Followings are version details:
- Affected version(s): < 5.58.2
- Patched version(s): 5.58.2
References
- GHSA-4gw3-8f77-f72c
- snyk.io
- www.debian.org
- www.npmjs.com
- www.oracle.com
- CVE-2020-7760
- CWE-400
- CAPEC-310
- OWASP 2021-A6
Related Issues
- Regular Expression Denial of Service (ReDoS) in lodash - CVE-2020-28500
- Knwl.js Regular Expression Denial of Service vulnerability - CVE-2020-26306
- Regular Expression Denial of Service in papaparse - CVE-2020-36649
- CommonRegexJS Regular Expression Denial of Service vulnerability - CVE-2020-26305
You might also like:
- Tags:
- npm
- codemirror
Anything's wrong? Let us know Last updated on February 01, 2023


