Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-26271

Опубликовано: 26 янв. 2021
Источник: debian

Описание

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ckeditorfixed4.16.0+dfsg-1package
ckeditorno-dsabusterpackage
ckeditorpostponedstretchpackage
ckeditor3not-affectedpackage

Примечания

  • https://github.com/ckeditor/ckeditor4/blob/major/CHANGES.md#ckeditor-416

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 5 лет назад

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).

CVSS3: 6.5
nvd
около 5 лет назад

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).

CVSS3: 6.5
github
больше 3 лет назад

CKEditor 4 ReDoS Vulnerability

CVSS3: 6.5
fstec
около 5 лет назад

Уязвимость плагина Advanced Tab for Dialogs WYSIWYG-редактора CKEditor, позволяющая нарушителю подделать содержимое адресной строки