QID 982246

QID 982246: Nodejs (npm) Security Update for codemirror (GHSA-4gw3-8f77-f72c)

This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2.
The vulnerable regular expression is located in https://github.com/codemirror/CodeMirror/blob/cdb228ac736369c685865b122b736cd0d397836c/mode/javascript/javascript.jsL129. The ReDOS vulnerability of the regex is mainly due to the sub-pattern (s|/*.*?*/)*

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-4gw3-8f77-f72c for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982246

    Software Advisories
    Advisory ID Software Component Link
    GHSA-4gw3-8f77-f72c codemirror URL Logo github.com/advisories/GHSA-4gw3-8f77-f72c