Clipboard feature vulnerability allowing to inject arbitrary HTML into the editor using paste functionality
- Severity:
- Medium
Description
The vulnerability has been discovered in clipboard plugin. All plugins with clipboard plugin dependency are affected:
- clipboard
- pastetext
- pastetools
- widget
- uploadwidget
- autolink
- tableselection
Recommendation
Update the ckeditor4 package to the latest compatible version. Followings are version details:
- Affected version(s): >= 4.5.2, < 4.16.2
- Patched version(s): 4.16.2
References
- GHSA-7889-rm5j-hpgg
- lists.fedoraproject.org
- www.oracle.com
- CVE-2021-32809
- CWE-79
- CWE-94
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- Widget feature vulnerability allowing to execute JavaScript code using undo functionality - CVE-2021-32808
- Fake objects feature vulnerability allowing to execute JavaScript code using malformed HTML. - CVE-2021-37695
- Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTML - CVE-2021-41164
- HTML comments vulnerability allowing to execute JavaScript code - CVE-2021-41165
You might also like:
- Tags:
- npm
- ckeditor4
Anything's wrong? Let us know Last updated on February 01, 2023


