Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rgg8-g5x8-wr9v

Опубликовано: 25 сент. 2024
Источник: github
Github: Прошло ревью
CVSS4: 5.1
CVSS3: 7.2

Описание

Cross-site scripting (XSS) in the clipboard package

Impact

During a recent internal audit, we identified a Cross-Site Scripting (XSS) vulnerability in the CKEditor 5 clipboard package. This vulnerability could be triggered by a specific user action, leading to unauthorized JavaScript code execution, if the attacker managed to insert a malicious content into the editor, which might happen with a very specific editor configuration.

This vulnerability affects only installations where the editor configuration meets the following criteria:

  1. The Block Toolbar plugin is enabled.
  2. One of the following plugins is also enabled:

Patches

The problem has been recognized and patched. The fix will be available in version 43.1.1 (and above), and explicitly in version 41.3.2.

Workarounds

It's highly recommended to update to the version 43.1.1 or higher. However, if the update is not an option, we recommend disabling the block toolbar plugin.

For more information

Email us at security@cksource.com if you have any questions or comments about this advisory.

Пакеты

Наименование

ckeditor5

npm
Затронутые версииВерсия исправления

>= 40.0.0, < 43.1.1

43.1.1

Наименование

@ckeditor/ckeditor5-clipboard

npm
Затронутые версииВерсия исправления

>= 40.0.0, < 43.1.1

43.1.1

EPSS

Процентиль: 44%
0.00219
Низкий

5.1 Medium

CVSS4

7.2 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 1 года назад

CKEditor 5 is a JavaScript rich-text editor. Starting in version 40.0.0 and prior to version 43.1.1, a Cross-Site Scripting (XSS) vulnerability is present in the CKEditor 5 clipboard package. This vulnerability could be triggered by a specific user action, leading to unauthorized JavaScript code execution, if the attacker managed to insert a malicious content into the editor, which might happen with a very specific editor configuration. This vulnerability only affects installations where the Block Toolbar plugin is enabled and either the General HTML Support (with a configuration that permits unsafe markup) or the HTML Embed plugin is also enabled. A fix for the problem is available in version 43.1.1. As a workaround, one may disable the block toolbar plugin.

CVSS3: 6.1
nvd
больше 1 года назад

CKEditor 5 is a JavaScript rich-text editor. Starting in version 40.0.0 and prior to version 43.1.1, a Cross-Site Scripting (XSS) vulnerability is present in the CKEditor 5 clipboard package. This vulnerability could be triggered by a specific user action, leading to unauthorized JavaScript code execution, if the attacker managed to insert a malicious content into the editor, which might happen with a very specific editor configuration. This vulnerability only affects installations where the Block Toolbar plugin is enabled and either the General HTML Support (with a configuration that permits unsafe markup) or the HTML Embed plugin is also enabled. A fix for the problem is available in version 43.1.1. As a workaround, one may disable the block toolbar plugin.

CVSS3: 6.1
debian
больше 1 года назад

CKEditor 5 is a JavaScript rich-text editor. Starting in version 40.0. ...

CVSS3: 6.1
fstec
больше 1 года назад

Уязвимость функции General HTML Support (GHS) и HTML embed панели инструментов Block Toolbar WYSIWYG-редактора CKEditor, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

EPSS

Процентиль: 44%
0.00219
Низкий

5.1 Medium

CVSS4

7.2 High

CVSS3

Дефекты

CWE-79