Description
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop resulting in a browser tab freeze. A patch is available in version 4.18.0. There are currently no known workarounds.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-29580 | CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop resulting in a browser tab freeze. A patch is available in version 4.18.0. There are currently no known workarounds. |
References
History
No history.
Subscriptions
Ckeditor
Subscribe
Ckeditor
Subscribe
Drupal
Subscribe
Drupal
Subscribe
Fedoraproject
Subscribe
Fedora
Subscribe
Oracle
Subscribe
Application Express
Subscribe
Commerce Merchandising
Subscribe
Financial Services Analytical Applications Infrastructure
Subscribe
Financial Services Behavior Detection Platform
Subscribe
Financial Services Trade-based Anti Money Laundering
Subscribe
Peoplesoft Enterprise Peopletools
Subscribe
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-23T18:53:35.902Z
Reserved: 2022-02-10T00:00:00.000Z
Link: CVE-2022-24729
No data.
Status : Modified
Published: 2022-03-16T17:15:07.943
Modified: 2024-11-21T06:50:57.993
Link: CVE-2022-24729
No data.
OpenCVE Enrichment
No data.
EUVD