QID 980367
QID 980367: Nodejs (npm) Security Update for ckeditor4 (GHSA-6226-h7ff-ch6c)
Security update has been released for ckeditor4 to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
A potential vulnerability has been discovered in CKEditor 4 [Widget](https://ckeditor.com/cke4/addon/widget) package. The vulnerability allowed to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version >= 4.13.0.
Solution
The problem has been recognized and patched. The fix will be available in version 4.16.2.
Vendor References
- GHSA-6226-h7ff-ch6c -
github.com/advisories/GHSA-6226-h7ff-ch6c
CVEs related to QID 980367
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6226-h7ff-ch6c | ckeditor4 |
|