QID 980067
QID 980067: Nodejs (npm) Security Update for ckeditor4 (GHSA-pvmx-g8h5-cprj)
Security update has been released for ckeditor4 to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
A potential vulnerability has been discovered in CKEditor 4 Advanced Content Filter (ACF) core module. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0.
Solution
The problem has been recognized and patched. The fix will be available in version 4.17.0.
Vendor References
- GHSA-pvmx-g8h5-cprj -
github.com/advisories/GHSA-pvmx-g8h5-cprj
CVEs related to QID 980067
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-pvmx-g8h5-cprj | ckeditor4 |
|