Vulnerabilities/

CKEditor 4 ReDoS Vulnerability

Severity:
Medium

Description

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).

Recommendation

Update the ckeditor4-dev package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
ckeditor4-dev
Anything's wrong? Let us know Last updated on April 22, 2024