QID 980067

QID 980067: Nodejs (npm) Security Update for ckeditor4 (GHSA-pvmx-g8h5-cprj)

Security update has been released for ckeditor4 to fix the vulnerability.

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

A potential vulnerability has been discovered in CKEditor 4 Advanced Content Filter (ACF) core module. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0.

  • CVSS V3 rated as Medium - 5.4 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution
    The problem has been recognized and patched. The fix will be available in version 4.17.0.
    Vendor References

    CVEs related to QID 980067

    Software Advisories
    Advisory ID Software Component Link
    GHSA-pvmx-g8h5-cprj ckeditor4 URL Logo github.com/advisories/GHSA-pvmx-g8h5-cprj