CVE-2020-7760


Regular Expression Denial of Service (ReDoS)

This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The vulnerable regular expression is located in https://github.com/codemirror/CodeMirror/blob/cdb228ac736369c685865b122b736cd0d397836c/mode/javascript/javascript.jsL129. The ReDOS vulnerability of the regex is mainly due to the sub-pattern (s|/*.*?*/)*



We have discovered 2,544 live websites that are affected by CVE-2020-7760.

Contact us to get more info




Affected Software

Product  CodeMirror
Category Editors
Vulnerable Versions
  • from 0 before 5.58.2
Total Vulnerable Versions107
Vulnerable Domains2,544 live websites (96.44% of CodeMirror install base)


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2020-7760 and the relative popularity of websites


Details

  • Published - Oct 30, 2020
  • Updated - Apr 20, 2022

Credits

  • Yeting Li




Countries

United States929 websites



France205 websites
Germany185 websites
GB125 websites
Czech Republic116 websites
South Africa106 websites
Netherlands69 websites
Russia59 websites
Italy51 websites
Canada47 websites

TLDs

.com1,013 websites
.org205 websites
.cz110 websites
.net104 websites
.de96 websites
.fr94 websites
.co.uk67 websites
.nl58 websites
.io42 websites
.ru41 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2020-7760 through included software libraries and plugins.



References


Websites affected by CVE-2020-7760

Top websites that are affected by CVE-2020-7760. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
*****.com ***
**********.com Nepal*,***
****.******.com United States*,***
********.io Austria**,***
****.********.com United States**,***
******.com United States**,***
****.********.me United States**,***
***.******.com United States**,***
******.*********.org United States**,***
*******.sk Slovakia**,***
See full domain list