3.1.0-incubating
12 years ago
12 years ago
Known vulnerabilities in the org.apache.marmotta.webjars:codemirror package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version | 
|---|---|
| 
 org.apache.marmotta.webjars:codemirror is a versatile text editor implemented in JavaScript for the browser. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) via multiple locations in  Note: The GitHub issue associated with the vulnerability refers to multiple problematic regex patterns; those patterns were introduced, in part, starting from version 2.33.0: 
 While the issue was reported for version 5.17.0, those patterns still exist in recent versions of the package except 6.x. How to fix Regular Expression Denial of Service (ReDoS)? A fix was pushed into the  | [0,) | 
| 
 org.apache.marmotta.webjars:codemirror is a versatile text editor implemented in JavaScript for the browser. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerable regular expression is located in https://github.com/codemirror/CodeMirror/blob/cdb228ac736369c685865b122b736cd0d397836c/mode/javascript/javascript.js#L129. The ReDOS vulnerability of the regex is mainly due to the sub-pattern  How to fix Regular Expression Denial of Service (ReDoS)? There is no fixed version for  | [0,) | 
| 
 org.apache.marmotta.webjars:codemirror is a versatile text editor implemented in JavaScript for the browser. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS). This regex
  How to fix Regular Expression Denial of Service (ReDoS)? There is no fixed version for  | [0,) |