CVE-2020-7760: Regular Expression Denial of Service (ReDoS)
This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The vulnerable regular expression is located in
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/codemirror-jsto a version that resolves this vulnerability.Fixed in 5.43.0-1+deb10u1Fixed in 5.59.2+~cs0.23.109-1Fixed in 5.65.0+~cs5.83.9-2Fixed in 5.65.0+~cs5.83.9-3
Event History
Frequently Asked Questions
What is CVE-2020-7760?
CVE-2020-7760 is a vulnerability that affects the Codemirror package before version 5.58.2.
What is the severity of CVE-2020-7760?
The severity of CVE-2020-7760 is high, with a severity value of 7.5.
What software is affected by CVE-2020-7760?
The Codemirror package before version 5.58.2, Oracle Application Express up to version 20.2, Oracle Enterprise Manager Express User Interface version 19c, Oracle Essbase version 21.2, Oracle Hyperion Data Relationship Management up to version 11.2.9.0, and Oracle Spatial Studio up to version 19.1.0 are affected by CVE-2020-7760.
How can I fix CVE-2020-7760 in the Codemirror package?
To fix CVE-2020-7760 in the Codemirror package, update to version 5.58.2 or later.
Where can I find more information about CVE-2020-7760?
You can find more information about CVE-2020-7760 at the following references: [Reference 1](https://github.com/codemirror/CodeMirror/commit/55d0333907117c9231ffdf555ae8824705993bbb), [Reference 2](https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEMARMOTTAWEBJARS-1024450), [Reference 3](https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1024449).