First published: Fri Oct 30 2020(Updated: )
Node.js codemirror module is vulnerable to a denial of service, caused by a regular expression denial of service (ReDoS) flaw. By using sub-pattern (s|/*.*?*/)*, a remote attacker could exploit this vulnerability to cause a denial of service condition.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
debian/codemirror-js | 5.43.0-1+deb10u1 5.59.2+~cs0.23.109-1 5.65.0+~cs5.83.9-2 5.65.0+~cs5.83.9-3 | |
Codemirror Codemirror | <5.58.2 | |
Oracle Application Express | <20.2 | |
Oracle Enterprise Manager Express User Interface | =19c | |
Oracle Essbase | =21.2 | |
Oracle Hyperion Data Relationship Management | <11.2.9.0 | |
Oracle Spatial Studio | <19.1.0 | |
IBM Cloud Pak for Business Automation | <=V23.0.1 - V23.0.1-IF001 | |
IBM Cloud Pak for Business Automation | <=V21.0.3 - V21.0.3-IF023 | |
IBM Cloud Pak for Business Automation | <=V22.0.2 - V22.0.2-IF006 and later fixes V22.0.1 - V22.0.1-IF006 and later fixes V21.0.2 - V21.0.2-IF012 and later fixes V21.0.1 - V21.0.1-IF007 and later fixes V20.0.1 - V20.0.3 and later fixes V19.0.1 - V19.0.3 and later fixes V18.0.0 - V18.0.2 and later fixes |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7760 is a vulnerability that affects the Codemirror package before version 5.58.2.
The severity of CVE-2020-7760 is high, with a severity value of 7.5.
The Codemirror package before version 5.58.2, Oracle Application Express up to version 20.2, Oracle Enterprise Manager Express User Interface version 19c, Oracle Essbase version 21.2, Oracle Hyperion Data Relationship Management up to version 11.2.9.0, and Oracle Spatial Studio up to version 19.1.0 are affected by CVE-2020-7760.
To fix CVE-2020-7760 in the Codemirror package, update to version 5.58.2 or later.
You can find more information about CVE-2020-7760 at the following references: [Reference 1](https://github.com/codemirror/CodeMirror/commit/55d0333907117c9231ffdf555ae8824705993bbb), [Reference 2](https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEMARMOTTAWEBJARS-1024450), [Reference 3](https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1024449).