CVE-2021-21254
Summary
| CVE | CVE-2021-21254 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-29 22:15:00 UTC |
| Updated | 2023-11-07 03:29:00 UTC |
| Description | CKEditor 5 is an open source rich text editor framework with a modular architecture. The CKEditor 5 Markdown plugin (@ckeditor/ckeditor5-markdown-gfm) before version 25.0.0 has a regex denial of service (ReDoS) vulnerability. The vulnerability allowed to abuse link recognition regular expression, which could cause a significant performance drop resulting in browser tab freeze. It affects all users using CKEditor 5 Markdown plugin at version <= 24.0.0. The problem has been recognized and patched. The fix will be available in version 25.0.0. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| @ckeditor/ckeditor5-markdown-gfm - npm |
MISC |
www.npmjs.com |
Release Notes, Third Party Advisory |
| Regular expression Denial of Service in Markdown plugin · Advisory · ckeditor/ckeditor5 · GitHub |
CONFIRM |
github.com |
Third Party Advisory |
| @ckeditor/ckeditor5-markdown-gfm - npm |
|
www.npmjs.com |
|
| Release v25.0.0 · ckeditor/ckeditor5 · GitHub |
MISC |
github.com |
Release Notes, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982962 Nodejs (npm) Security Update for @ckeditor/ckeditor5-markdown-gfm (GHSA-hgmg-hhc8-g5wr)