CVE-2020-7760
Summary
| CVE | CVE-2020-7760 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-10-30 11:15:00 UTC |
| Updated | 2022-05-12 14:47:00 UTC |
| Description | This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The vulnerable regular expression is located in https://github.com/codemirror/CodeMirror/blob/cdb228ac736369c685865b122b736cd0d397836c/mode/javascript/javascript.jsL129. The ReDOS vulnerability of the regex is mainly due to the sub-pattern (s|/*.*?*/)* |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Debian -- Security Information -- DSA-4789-1 codemirror-js |
DEBIAN |
www.debian.org |
Third Party Advisory |
| Regular Expression Denial of Service (ReDoS) in org.webjars.bowergithub.codemirror:codemirror | Snyk |
CONFIRM |
snyk.io |
Exploit, Third Party Advisory |
| [javascript mode] Fix potentially-exponential regexp · codemirror/CodeMirror@55d0333 · GitHub |
CONFIRM |
github.com |
Patch, Third Party Advisory |
| Regular Expression Denial of Service (ReDoS) in org.webjars:codemirror | Snyk |
CONFIRM |
snyk.io |
Exploit, Third Party Advisory |
| Oracle Critical Patch Update Advisory - April 2022 |
MISC |
www.oracle.com |
|
| Oracle Critical Patch Update Advisory - July 2021 |
N/A |
www.oracle.com |
|
| Regular Expression Denial of Service (ReDoS) in org.webjars.bowergithub.components:codemirror | Snyk |
CONFIRM |
snyk.io |
Exploit, Third Party Advisory |
| Regular Expression Denial of Service (ReDoS) in org.webjars.bower:codemirror | Snyk |
CONFIRM |
snyk.io |
Exploit, Third Party Advisory |
| Regular Expression Denial of Service (ReDoS) in org.apache.marmotta.webjars:codemirror | Snyk |
CONFIRM |
snyk.io |
Exploit, Third Party Advisory |
| Regular Expression Denial of Service (ReDoS) in org.webjars.npm:codemirror | Snyk |
CONFIRM |
snyk.io |
Exploit, Third Party Advisory |
| Regular Expression Denial of Service (ReDoS) in codemirror | Snyk |
CONFIRM |
snyk.io |
Exploit, Third Party Advisory |
| Oracle Critical Patch Update Advisory - April 2021 |
MISC |
www.oracle.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Yeting Li
Legacy QID Mappings
- 20215 Oracle Database 19c Critical Patch Update - April 2021
- 20216 Oracle Database 18c Critical Patch Update - April 2021
- 20217 Oracle Database 12.2.0.1 Critical Patch Update - April 2021
- 20218 Oracle Database 12.2.0.1 Critical Patch Update - April 2021 (Unauthenticated)
- 20219 Oracle Database 12.1.0.2 Critical Patch Update - April 2021
- 20220 Oracle Database 12.1.0.2 Critical Patch Update - April 2021 (Unauthenticated)
- 20226 Oracle Database 19c Critical Patch Update - July 2021
- 20279 Oracle Database 19c Critical OJVM Patch Update - July 2021
- 376115 IBM Integration Bus Node.js Denial of Service (DoS) Vulnerability (6416609)
- 982246 Nodejs (npm) Security Update for codemirror (GHSA-4gw3-8f77-f72c)