PT-2020-5773 · Apache+1 · Org.Apache.Marmotta.Webjars:Codemirror+1

Yeting Li

·

Published

2020-10-01

·

Updated

2022-05-12

·

CVE-2020-7760

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions: codemirror versions prior to 5.58.2 org.apache.marmotta.webjars:codemirror versions prior to 5.58.2
Description: The issue is related to a ReDOS vulnerability in the regular expression of the codemirror package. This vulnerability is mainly due to the sub-pattern (s|/*.*?*/)* located in the javascript.js file. The vulnerability can be exploited by a remote attacker to cause a denial of service.
Recommendations: For codemirror versions prior to 5.58.2, update to version 5.58.2 or later. For org.apache.marmotta.webjars:codemirror versions prior to 5.58.2, update to version 5.58.2 or later. As a temporary workaround, consider disabling the vulnerable regular expression in the javascript.js file until a patch is available.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01732
CVE-2020-7760
DSA-4789-1
GHSA-4GW3-8F77-F72C
SNYK-JAVA-ORGAPACHEMARMOTTAWEBJARS-1024450
SNYK-JAVA-ORGWEBJARS-1024449
SNYK-JAVA-ORGWEBJARSBOWER-1024445
SNYK-JAVA-ORGWEBJARSBOWERGITHUBCODEMIRROR-1024448
SNYK-JAVA-ORGWEBJARSBOWERGITHUBCOMPONENTS-1024446
SNYK-JAVA-ORGWEBJARSNPM-1024447
SNYK-JS-CODEMIRROR-1016937

Affected Products

Codemirror
Org.Apache.Marmotta.Webjars:Codemirror