CVE-2021-41165
Summary
| CVE | CVE-2021-41165 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-11-17 20:15:00 UTC |
| Updated | 2022-10-05 12:47:00 UTC |
| Description | CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Access to this page has been denied. |
CONFIRM |
www.drupal.org |
|
| Oracle Critical Patch Update Advisory - April 2022 |
MISC |
www.oracle.com |
|
| Oracle Critical Patch Update Advisory - January 2022 |
MISC |
www.oracle.com |
|
| ckeditor4/CHANGES.md at major · ckeditor/ckeditor4 · GitHub |
MISC |
github.com |
|
| HTML comments vulnerability allowing to execute JavaScript code · Advisory · ckeditor/ckeditor4 · GitHub |
CONFIRM |
github.com |
|
| Oracle Critical Patch Update Advisory - July 2022 |
N/A |
www.oracle.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 154106 Drupal Core Cross-Site Scripting (XSS) Vulnerability (SA-CORE-2021-011)
- 182393 Debian Security Update for ckeditor (CVE-2021-41165)
- 283229 Fedora Security Update for ckeditor (FEDORA-2022-b61dfd219b)
- 283475 Fedora Security Update for ckeditor (FEDORA-2022-4c634ee466)
- 376547 Oracle PeopleSoft Enterprise PeopleTools Product Multiple Vulnerabilities (CPUAPR2022)
- 730266 Drupal Core Cross-Site Scripting (XSS) Vulnerability (SA-CORE-2021-011)
- 980068 Nodejs (npm) Security Update for ckeditor4 (GHSA-7h26-63m7-qhf2)
- 997876 PHP (Composer) Security Update for ckeditor/ckeditor (GHSA-7h26-63m7-qhf2)