Lucene search

K
osvGoogleOSV:GHSA-JV4C-7JQQ-M34X
HistoryMay 24, 2022 - 5:40 p.m.

CKEditor 4 ReDoS Vulnerability

2022-05-2417:40:21
Google
osv.dev
8
redos attack
ckeditor 4
vulnerability
styles input
dialogs plugin

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

51.0%

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

51.0%