Description
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML, which could result in injecting arbitrary HTML into the editor. It affects all users using the CKEditor 4 plugins listed above at version >= 4.5.2. The problem has been recognized and patched. The fix will be available in version 4.16.2.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-1613 | ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML, which could result in injecting arbitrary HTML into the editor. It affects all users using the CKEditor 4 plugins listed above at version >= 4.5.2. The problem has been recognized and patched. The fix will be available in version 4.16.2. |
Github GHSA |
GHSA-7889-rm5j-hpgg | Clipboard feature vulnerability allowing to inject arbitrary HTML into the editor using paste functionality |
Ubuntu USN |
USN-5340-1 | CKEditor vulnerabilities |
Ubuntu USN |
USN-5340-2 | CKEditor vulnerabilities |
References
History
No history.
Subscriptions
Ckeditor
Subscribe
Ckeditor
Subscribe
Fedoraproject
Subscribe
Fedora
Subscribe
Oracle
Subscribe
Application Express
Subscribe
Banking Party Management
Subscribe
Commerce Guided Search
Subscribe
Commerce Merchandising
Subscribe
Documaker
Subscribe
Financial Services Analytical Applications Infrastructure
Subscribe
Jd Edwards Enterpriseone Tools
Subscribe
Peoplesoft Enterprise Peopletools
Subscribe
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-03T23:33:56.090Z
Reserved: 2021-05-12T00:00:00.000Z
Link: CVE-2021-32809
No data.
Status : Modified
Published: 2021-08-12T17:15:08.167
Modified: 2024-11-21T06:07:47.520
Link: CVE-2021-32809
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA
Ubuntu USN