CVE-2020-7760: Regular Expression Denial of Service (ReDoS)
Node.js codemirror module is vulnerable to a denial of service, caused by a regular expression denial of service (ReDoS) flaw. By using sub-pattern (s|/*.*?*/)*, a remote attacker could exploit this vulnerability to cause a denial of service condition.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-7760?
CVE-2020-7760 is a vulnerability that affects the Codemirror package before version 5.58.2.
What is the severity of CVE-2020-7760?
The severity of CVE-2020-7760 is high, with a severity value of 7.5.
What software is affected by CVE-2020-7760?
The Codemirror package before version 5.58.2, Oracle Application Express up to version 20.2, Oracle Enterprise Manager Express User Interface version 19c, Oracle Essbase version 21.2, Oracle Hyperion Data Relationship Management up to version 11.2.9.0, and Oracle Spatial Studio up to version 19.1.0 are affected by CVE-2020-7760.
How can I fix CVE-2020-7760 in the Codemirror package?
To fix CVE-2020-7760 in the Codemirror package, update to version 5.58.2 or later.
Where can I find more information about CVE-2020-7760?
You can find more information about CVE-2020-7760 at the following references: [Reference 1](https://github.com/codemirror/CodeMirror/commit/55d0333907117c9231ffdf555ae8824705993bbb), [Reference 2](https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEMARMOTTAWEBJARS-1024450), [Reference 3](https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1024449).