Bangtrongtuyet / phpmyAdmin

GNU General Public License v2.0
0 stars 0 forks source link

CVE-2020-7760 (High) detected in codemirror-5.45.0.tgz #23

Open mend-bolt-for-github[bot] opened 3 years ago

mend-bolt-for-github[bot] commented 3 years ago

CVE-2020-7760 - High Severity Vulnerability

Vulnerable Library - codemirror-5.45.0.tgz

Full-featured in-browser code editor

Library home page: https://registry.npmjs.org/codemirror/-/codemirror-5.45.0.tgz

Path to dependency file: /phpmyAdmin/package.json

Path to vulnerable library: /node_modules/codemirror/package.json

Dependency Hierarchy: - :x: **codemirror-5.45.0.tgz** (Vulnerable Library)

Vulnerability Details

This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The vulnerable regular expression is located in https://github.com/codemirror/CodeMirror/blob/cdb228ac736369c685865b122b736cd0d397836c/mode/javascript/javascript.jsL129. The ReDOS vulnerability of the regex is mainly due to the sub-pattern (s|/*.*?*/)*

Publish Date: 2020-10-30

URL: CVE-2020-7760

CVSS 3 Score Details (7.5)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: None - Integrity Impact: None - Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7760

Release Date: 2020-10-30

Fix Resolution: 5.58.2


Step up your Open Source Security Game with Mend here