CVE-2022-23474
Summary
| CVE | CVE-2022-23474 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-15 19:15:00 UTC |
| Updated | 2022-12-20 01:56:00 UTC |
| Description | Editor.js is a block-style editor with clean JSON output. Versions prior to 2.26.0 are vulnerable to Code Injection via pasted input. The processHTML method passes pasted input into wrapper’s innerHTML. This issue is patched in version 2.26.0. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| fix(tools-api): pasteConfig.tags now supports a sanitize config by robonetphy · Pull Request #2100 · codex-team/editor.js · GitHub | MISC | github.com | |
| GHSL-2022-028: Copy/paste cross-site scripting (XSS) in codex-team | GitHub Security Lab | MISC | securitylab.github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.