CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:N/I:N/A:P
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS
Percentile
76.0%
CKEditor 5 provides a WYSIWYG editing solution. This CVE affects the
following npm packages: ckeditor5-engine, ckeditor5-font, ckeditor5-image,
ckeditor5-list, ckeditor5-markdown-gfm, ckeditor5-media-embed,
ckeditor5-paste-from-office, and ckeditor5-widget. Following an internal
audit, a regular expression denial of service (ReDoS) vulnerability has
been discovered in multiple CKEditor 5 packages. The vulnerability allowed
to abuse particular regular expressions, which could cause a significant
performance drop resulting in a browser tab freeze. It affects all users
using the CKEditor 5 packages listed above at version <= 26.0.0. The
problem has been recognized and patched. The fix will be available in
version 27.0.0.
Author | Note |
---|---|
litios | This only affects CKEditor 5 and all releases currently use CKEditor 4 (2022-03-16) |
github.com/ckeditor/ckeditor5/security/advisories/GHSA-3rh3-wfr4-76mj
launchpad.net/bugs/cve/CVE-2021-21391
nvd.nist.gov/vuln/detail/CVE-2021-21391
security-tracker.debian.org/tracker/CVE-2021-21391
www.cve.org/CVERecord?id=CVE-2021-21391
www.npmjs.com/package/@ckeditor/ckeditor5-engine
www.npmjs.com/package/@ckeditor/ckeditor5-font
www.npmjs.com/package/@ckeditor/ckeditor5-image
www.npmjs.com/package/@ckeditor/ckeditor5-list
www.npmjs.com/package/@ckeditor/ckeditor5-markdown-gfm
www.npmjs.com/package/@ckeditor/ckeditor5-media-embed
www.npmjs.com/package/@ckeditor/ckeditor5-paste-from-office
www.npmjs.com/package/@ckeditor/ckeditor5-widget
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:N/I:N/A:P
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS
Percentile
76.0%