QID 980092
QID 980092: Nodejs (npm) Security Update for ckeditor4 (GHSA-m94c-37g6-cjhc)
Security update has been released for ckeditor4 to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version < 4.16.2.
Solution
The problem has been recognized and patched. The fix will be available in version 4.16.2.
Vendor References
- GHSA-m94c-37g6-cjhc -
github.com/advisories/GHSA-m94c-37g6-cjhc
CVEs related to QID 980092
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-m94c-37g6-cjhc | ckeditor4 |
|