Описание
ckeditor4 vulnerable to cross-site scripting
A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!>
is mishandled.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-33829
- https://ckeditor.com/blog/ckeditor-4.16.1-with-accessibility-enhancements/#improvements-for-comments-in-html-parser
- https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/core/CVE-2021-33829.yaml
- https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/drupal/CVE-2021-33829.yaml
- https://lists.debian.org/debian-lts-announce/2021/11/msg00007.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NYA354LJP47KCVJMTUO77ZCX3ZK42G3T
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UVOYN2WKDPLKCNILIGEZM236ABQASLGW
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WAGNWHFIQAVCP537KFFS2A2GDG66J7XD
- https://www.drupal.org/sa-core-2021-003
- https://www.npmjs.com/package/ckeditor4
Пакеты
ckeditor4
>= 4.14.0, < 4.16.1
4.16.1
drupal/core
>= 7.0.0, < 7.80
7.80
drupal/core
>= 8.0.0, < 8.9.16
8.9.16
drupal/core
>= 9.0.0, < 9.0.14
9.0.14
drupal/core
>= 9.1.0, < 9.1.9
9.1.9
drupal/drupal
>= 7.0.0, < 7.80
7.80
drupal/drupal
>= 8.0.0, < 8.9.16
8.9.16
drupal/drupal
>= 9.0.0, < 9.0.14
9.0.14
drupal/drupal
>= 9.1.0, < 9.1.9
9.1.9
Связанные уязвимости
A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.
A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.
A cross-site scripting (XSS) vulnerability in the HTML Data Processor ...
Уязвимость WYSIWYG-редактора CKEditor, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю оказать воздействие на целостность данных