Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-24729

Опубликовано: 16 мар. 2022
Источник: debian
EPSS Низкий

Описание

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop resulting in a browser tab freeze. A patch is available in version 4.18.0. There are currently no known workarounds.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ckeditorfixed4.19.0+dfsg-1package
ckeditorno-dsabullseyepackage
ckeditorno-dsabusterpackage
ckeditor3not-affectedpackage

Примечания

  • https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-f6rf-9m92-x2hh

  • https://github.com/ckeditor/ckeditor4/commit/8cff1e5aee3d766068792a374ba6b54a5cb92e2d (4.18.0)

EPSS

Процентиль: 63%
0.00445
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 3 лет назад

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop resulting in a browser tab freeze. A patch is available in version 4.18.0. There are currently no known workarounds.

CVSS3: 6.5
nvd
больше 3 лет назад

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop resulting in a browser tab freeze. A patch is available in version 4.18.0. There are currently no known workarounds.

CVSS3: 6.5
fstec
больше 3 лет назад

Уязвимость плагина dialog WYSIWYG-редактора CKEditor, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 63%
0.00445
Низкий