This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The vulnerable regular expression is located in https://github.com/codemirror/CodeMirror/blob/cdb228ac736369c685865b122b736cd0d397836c/mode/javascript/javascript.jsL129. The ReDOS vulnerability of the regex is mainly due to the sub-pattern (s|/*.*?*/)*
2020-10-30T11:15:12.633
2024-11-21T05:37:45.027
Modified
CVSSv3.1: 5.3 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | codemirror | codemirror | < 5.58.2 | Yes |
Application | oracle | application_express | < 20.2 | Yes |
Application | oracle | enterprise_manager_express_user_interface | 19c | Yes |
Application | oracle | essbase | 21.2 | Yes |
Application | oracle | hyperion_data_relationship_management | < 11.2.9.0 | Yes |
Application | oracle | spatial_studio | < 19.1.0 | Yes |