Resource exhaustion in Codemirror - CVE-2020-7760

 

Resource exhaustion in Codemirror - CVE-2020-7760

Published: April 21, 2021


Vulnerability identifier: #VU52384
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-7760
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when processing regular expression. A remote attacker can trigger resource exhaustion and perform a regular expression denial of service (ReDoS) attack.


Affected software

Codemirror
Debian Linux
watsonx.data
Oracle Utilties Application Framework
Oracle Utilities Application Framework
Oracle Business Intelligence Enterprise Edition
Oracle Siebel CRM
Oracle Communications Diameter Signaling Router
IBM Cloud Automation Manager
Oracle Hyperion Data Relationship Management
IBM Cloud Pak for Business Automation
Oracle Spatial Studio
Oracle Database Server
Oracle Essbase
Oracle Application Express
codemirror-js (Debian package)

How to mitigate CVE-2020-7760

Install updates from vendor's website.

Codemirror - update to 5.58.2
watsonx.data - update to 2.2.2
Oracle Spatial Studio - update to 19.1.0
Oracle Application Express - update to 20.2
IBM Cloud Automation Manager - update to 4.2.0.1 iFix 2
codemirror-js (Debian package) - update to 5.43.0-1+deb10u1
Oracle Hyperion Data Relationship Management - update to 11.2.9.0
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.24, 23.0.1.2

External References

Related Security Bulletins