Description
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
Recommendation
Update the ckeditor4-dev package to the latest compatible version. Followings are version details:
- Affected version(s): < 4.16
- Patched version(s): 4.16
References
Related Issues
- Mind-elixir Cross-site Scripting vulnerability - CVE-2021-32851
- textAngular Cross-site Scripting vulnerability - CVE-2021-32854
- ReDOS in IS-SVG - CVE-2021-29059
- iziModal Cross-site Scripting vulnerability - CVE-2021-32860
You might also like:
- Tags:
- npm
- ckeditor4-dev
Anything's wrong? Let us know Last updated on April 22, 2024


