Denial of service in CKEditor

Published: 2021-01-27


Risk
Low
Patch available
YES
Number of vulnerabilities
2
CVE ID
CVE-2021-26271CVE-2021-26272
CWE ID
CWE-20
Exploitation vector
Network
Public exploit
N/A
Vulnerable softwareSubscribe
CKEditorWeb applications / JS libraries
Vendor
CKSource

Security Advisory



1) Input validation error


Risk: Low


CVSSv3: 4.1 [CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L/E:U/RL:O/RC:C] [PCI]


CVE-ID: CVE-2021-26271


CWE-ID: CWE-20 - Improper Input Validation


Exploit availability: No


Description

The vulnerability allows a remote attacker to perform a regular expression denial of service (ReDoS) attack.


The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can trick the victim to paste a specially crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin) and perform a regular expression denial of service (ReDoS) attack.


Mitigation

Install updates from vendor's website.


Vulnerable software versions

CKEditor: 4.0.0, 4.0.1, 4.0.1.1, 4.0.2, 4.0.3, 4.1.0, 4.1.1, 4.1.2, 4.1.3, 4.2.0, 4.2.1, 4.2.2, 4.2.3, 4.3.0, 4.3.1, 4.3.2, 4.3.3, 4.3.4, 4.3.5, 4.4.0, 4.4.1, 4.4.2, 4.4.3, 4.4.4, 4.4.5, 4.4.6, 4.4.7, 4.4.8, 4.5.0, 4.5.1, 4.5.2, 4.5.3, 4.5.4, 4.5.5, 4.5.6, 4.5.7, 4.5.8, 4.5.9, 4.5.10, 4.5.11, 4.6.0, 4.6.1, 4.6.2, 4.7.0, 4.7.1, 4.7.2, 4.7.3, 4.8.0, 4.9.0, 4.9.1, 4.9.2, 4.10.0, 4.10.1, 4.11.0, 4.11.1, 4.11.2, 4.11.3, 4.11.4, 4.12.0, 4.12.1, 4.13.0, 4.13.1, 4.14.0, 4.14.1, 4.15.0, 4.15.1


CPE
External links

https://github.com/ckeditor/ ..

Support the originator by clicking the read the rest link below.