QID 980368

QID 980368: Nodejs (npm) Security Update for ckeditor4 (GHSA-7889-rm5j-hpgg)

Security update has been released for ckeditor4 to fix the vulnerability.

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML, which could result in injecting arbitrary HTML into the editor. It affects all users using the CKEditor 4 plugins listed above at version >= 4.5.2.

  • CVSS V3 rated as Medium - 5.4 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution
    The problem has been recognized and patched. The fix will be available in version 4.16.2.
    Vendor References

    CVEs related to QID 980368

    Software Advisories
    Advisory ID Software Component Link
    GHSA-7889-rm5j-hpgg ckeditor4 URL Logo github.com/advisories/GHSA-7889-rm5j-hpgg