Описание
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
Ссылки
- Vendor Advisory
- Release NotesThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Vendor Advisory
- Release NotesThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 4.0 (включая) до 4.16 (исключая)
cpe:2.3:a:ckeditor:ckeditor:*:*:*:*:*:*:*:*
Конфигурация 2Версия до 21.1.0 (исключая)Версия от 8.0.6 (включая) до 8.0.9 (включая)Версия до 9.2.6.0 (исключая)Версия до 21.9 (исключая)
Одно из
cpe:2.3:a:oracle:agile_plm:9.3.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
cpe:2.3:a:oracle:application_express:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:siebel_ui_framework:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_sites:12.2.1.3.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*
EPSS
Процентиль: 62%
0.00428
Низкий
6.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-829
Связанные уязвимости
CVSS3: 6.5
ubuntu
около 5 лет назад
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
CVSS3: 6.5
debian
около 5 лет назад
It was possible to execute a ReDoS-type attack inside CKEditor 4 befor ...
CVSS3: 6.5
fstec
около 5 лет назад
Уязвимость плагина Advanced Tab for Dialogs WYSIWYG-редактора CKEditor, позволяющая нарушителю подделать содержимое адресной строки
EPSS
Процентиль: 62%
0.00428
Низкий
6.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-829