QID 980068
QID 980068: Nodejs (npm) Security Update for ckeditor4 (GHSA-7h26-63m7-qhf2)
Security update has been released for ckeditor4 to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
A potential vulnerability has been discovered in CKEditor 4 HTML processing core module. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0.
Solution
The problem has been recognized and patched. The fix will be available in version 4.17.0.
Vendor References
- GHSA-7h26-63m7-qhf2 -
github.com/advisories/GHSA-7h26-63m7-qhf2
CVEs related to QID 980068
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-7h26-63m7-qhf2 | ckeditor4 |
|