Total vulnerabilities in the database
This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The vulnerable regular expression is located in https://github.com/codemirror/CodeMirror/blob/cdb228ac736369c685865b122b736cd0d397836c/mode/javascript/javascript.jsL129. The ReDOS vulnerability of the regex is mainly due to the sub-pattern (s|/.?/)
Software | From | Fixed in |
---|---|---|
codemirror / codemirror | - | 5.58.2 |
oracle / application_express | - | 20.2 |
oracle / essbase | 21.2 | 21.2.x |
oracle / enterprise_manager_express_user_interface | 19c | 19c.x |
oracle / hyperion_data_relationship_management | - | 11.2.9.0 |
oracle / spatial_studio | - | 19.1.0 |
![]() |
- | 5.58.2 |