Описание
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
Ссылки
- Vendor Advisory
- Release NotesThird Party Advisory
- PatchThird Party Advisory
- Not ApplicableThird Party Advisory
- PatchThird Party Advisory
- Vendor Advisory
- Release NotesThird Party Advisory
- PatchThird Party Advisory
- Not ApplicableThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Одно из
EPSS
6.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
Связанные уязвимости
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
It was possible to execute a ReDoS-type attack inside CKEditor 4 befor ...
Inclusion of Functionality from Untrusted Control Sphere in CKEditor 4
Уязвимость плагина Autolink WYSIWYG-редактора CKEditor , связанная с включением функций из недостоверной контролируемой области, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
6.5 Medium
CVSS3
4.3 Medium
CVSS2