VDB
Sign up
MEDIUM6.5

GHSA-jv4c-7jqq-m34x

CKEditor 4 ReDoS Vulnerability

Quick fix

GHSA-jv4c-7jqq-m34x — ckeditor4-dev: upgrade to the fixed version with the command below.

npm install ckeditor4-dev@4.16

Details

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/ckeditor4-dev
Introduced in: 0Fixed in: 4.16
Fixnpm install ckeditor4-dev@4.16

References