MEDIUM6.5
GHSA-jv4c-7jqq-m34x
CKEditor 4 ReDoS Vulnerability
Quick fix
GHSA-jv4c-7jqq-m34x — ckeditor4-dev: upgrade to the fixed version with the command below.
npm install ckeditor4-dev@4.16Details
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-26271[ADVISORY]
- https://github.com/ckeditor/ckeditor4[PACKAGE]
- https://github.com/ckeditor/ckeditor4/blob/major/CHANGES.md#ckeditor-416[WEB]
- https://web.archive.org/web/20210128132707/https://ckeditor.com/blog/CKEditor-4.16-with-improved-image-pasting-High-Contrast-support-and-a-new-color-API/#security-comes-first[WEB]
- https://www.oracle.com//security-alerts/cpujul2021.html[WEB]
- https://www.oracle.com/security-alerts/cpuoct2021.html[WEB]