CVE-2021-26272
Summary
| CVE | CVE-2021-26272 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-26 21:15:00 UTC |
| Updated | 2022-03-01 17:18:00 UTC |
| Description | It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin). |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| ckeditor4/CHANGES.md at major · ckeditor/ckeditor4 · GitHub |
MISC |
github.com |
Release Notes, Third Party Advisory |
| Oracle Critical Patch Update Advisory - July 2021 |
N/A |
www.oracle.com |
|
| Oracle Critical Patch Update Advisory - October 2021 |
MISC |
www.oracle.com |
|
| Oracle Critical Patch Update Advisory - January 2022 |
MISC |
www.oracle.com |
|
| CKEditor 4.16 with improved image pasting, High Contrast support and a new color API |
MISC |
ckeditor.com |
Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179922 Debian Security Update for ckeditor (CVE-2021-26272)
- 20232 Oracle Database 21c Critical Patch Update - October 2021
- 20233 Oracle Database 19c Critical Patch Update - October 2021
- 20234 Oracle Database 12.2.0.1 Critical Patch Update - October 2021
- 20235 Oracle Database 12.2.0.1 Critical Patch Update - October 2021 (Unauthenticated)
- 20237 Oracle Database 12.1.0.2 Critical Patch Update - October 2021
- 20238 Oracle Database 12.1.0.2 Critical Patch Update - October 2021 (Unauthenticated)
- 980331 Nodejs (npm) Security Update for ckeditor4 (GHSA-wpvm-wqr4-p7cw)