Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-24728

Опубликовано: 16 мар. 2022
Источник: debian
EPSS Низкий

Описание

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ckeditorfixed4.19.0+dfsg-1package
ckeditorno-dsabullseyepackage
ckeditorno-dsabusterpackage
ckeditor3removedpackage
ckeditor3ignoredbookwormpackage
ckeditor3no-dsabullseyepackage
ckeditor3end-of-lifebusterpackage
ckeditor3end-of-lifestretchpackage

Примечания

  • https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-4fc4-4p5g-6w89

  • https://github.com/ckeditor/ckeditor4/commit/d158413449692d920a778503502dcb22881bc949 (4.18.0)

  • MITRE's referenced patch (above) does not seem related

EPSS

Процентиль: 70%
0.00668
Низкий

Связанные уязвимости

CVSS3: 5.4
ubuntu
больше 3 лет назад

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.

CVSS3: 5.4
nvd
больше 3 лет назад

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.

CVSS3: 5.4
github
больше 3 лет назад

Cross-site Scripting in CKEditor4

EPSS

Процентиль: 70%
0.00668
Низкий