QID 980068

QID 980068: Nodejs (npm) Security Update for ckeditor4 (GHSA-7h26-63m7-qhf2)

Security update has been released for ckeditor4 to fix the vulnerability.

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

A potential vulnerability has been discovered in CKEditor 4 HTML processing core module. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0.

  • CVSS V3 rated as Medium - 5.4 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution
    The problem has been recognized and patched. The fix will be available in version 4.17.0.
    Vendor References

    CVEs related to QID 980068

    Software Advisories
    Advisory ID Software Component Link
    GHSA-7h26-63m7-qhf2 ckeditor4 URL Logo github.com/advisories/GHSA-7h26-63m7-qhf2