Lucene search

K
osvGoogleOSV:GHSA-WPVM-WQR4-P7CW
HistoryOct 13, 2021 - 3:34 p.m.

Inclusion of Functionality from Untrusted Control Sphere in CKEditor 4

2021-10-1315:34:09
Google
osv.dev
10

0.002 Low

EPSS

Percentile

53.2%

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).

CPENameOperatorVersion
ckeditor4lt4.16.0