Vulnerabilities/

Inclusion of Functionality from Untrusted Control Sphere in CKEditor 4

Severity:
Medium

Description

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).

Recommendation

Update the ckeditor4 package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
ckeditor4
Anything's wrong? Let us know Last updated on February 01, 2023