QID 982246
QID 982246: Nodejs (npm) Security Update for codemirror (GHSA-4gw3-8f77-f72c)
This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2.
The vulnerable regular expression is located in https://github.com/codemirror/CodeMirror/blob/cdb228ac736369c685865b122b736cd0d397836c/mode/javascript/javascript.jsL129. The ReDOS vulnerability of the regex is mainly due to the sub-pattern (s|/*.*?*/)*
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-4gw3-8f77-f72c for updates pertaining to this vulnerability.
Vendor References
- GHSA-4gw3-8f77-f72c -
github.com/advisories/GHSA-4gw3-8f77-f72c
CVEs related to QID 982246
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4gw3-8f77-f72c | codemirror |
|