MEDIUM · 5.3

CVE-2020-7760

This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The vulnerable regular expression is located in https://github.com/codemirror/CodeM...

Vulnerability Description

This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The vulnerable regular expression is located in https://github.com/codemirror/CodeMirror/blob/cdb228ac736369c685865b122b736cd0d397836c/mode/javascript/javascript.jsL129. The ReDOS vulnerability of the regex is mainly due to the sub-pattern (s|/*.*?*/)*

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
LOW

Affected Products

VendorProductVersions
CodemirrorCodemirror< 5.58.2
OracleApplication Express< 20.2
OracleEnterprise Manager Express User Interface19c
OracleEssbase21.2
OracleHyperion Data Relationship Management< 11.2.9.0
OracleSpatial Studio< 19.1.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-7760?

CVE-2020-7760 is a vulnerability with a CVSS score of 5.3 (MEDIUM). This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The vulnerable regular expression is located in https://github.com/codemirror/CodeM...

How severe is CVE-2020-7760?

CVE-2020-7760 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-7760?

Check the references section above for vendor advisories and patch information. Affected products include: Codemirror Codemirror, Oracle Application Express, Oracle Enterprise Manager Express User Interface, Oracle Essbase, Oracle Hyperion Data Relationship Management.