ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version < 4.16.2. The problem has been recognized and patched. The fix will be available in version 4.16.2.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Ckeditor
Subscribe
|
Ckeditor
Subscribe
|
|
Debian
Subscribe
|
Debian Linux
Subscribe
|
|
Fedoraproject
Subscribe
|
Fedora
Subscribe
|
|
Oracle
Subscribe
|
Application Express
Subscribe
Banking Party Management
Subscribe
Commerce Guided Search
Subscribe
Commerce Merchandising
Subscribe
Documaker
Subscribe
Financial Services Analytical Applications Infrastructure
Subscribe
Financial Services Model Management And Governance
Subscribe
Jd Edwards Enterpriseone Tools
Subscribe
Peoplesoft Enterprise Peopletools
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2813-1 | ckeditor security update |
EUVD |
EUVD-2021-1795 | ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version < 4.16.2. The problem has been recognized and patched. The fix will be available in version 4.16.2. |
Github GHSA |
GHSA-m94c-37g6-cjhc | Fake objects feature vulnerability allowing to execute JavaScript code using malformed HTML. |
Ubuntu USN |
USN-5340-1 | CKEditor vulnerabilities |
Ubuntu USN |
USN-5340-2 | CKEditor vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-04T01:23:01.506Z
Reserved: 2021-07-29T00:00:00
Link: CVE-2021-37695
No data.
Status : Modified
Published: 2021-08-13T00:15:07.397
Modified: 2024-11-21T06:15:43.433
Link: CVE-2021-37695
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Github GHSA
Ubuntu USN