Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-21391
HistoryApr 29, 2021 - 12:00 a.m.

CVE-2021-21391

2021-04-2900:00:00
ubuntu.com
ubuntu.com
15
cve-2021-21391
ckeditor 5
redos
vulnerability
npm packages
regex denial of service
performance drop
browser freeze
version 26.0.0
version 27.0.0
patch

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.005

Percentile

76.0%

CKEditor 5 provides a WYSIWYG editing solution. This CVE affects the
following npm packages: ckeditor5-engine, ckeditor5-font, ckeditor5-image,
ckeditor5-list, ckeditor5-markdown-gfm, ckeditor5-media-embed,
ckeditor5-paste-from-office, and ckeditor5-widget. Following an internal
audit, a regular expression denial of service (ReDoS) vulnerability has
been discovered in multiple CKEditor 5 packages. The vulnerability allowed
to abuse particular regular expressions, which could cause a significant
performance drop resulting in a browser tab freeze. It affects all users
using the CKEditor 5 packages listed above at version <= 26.0.0. The
problem has been recognized and patched. The fix will be available in
version 27.0.0.

Notes

Author Note
litios This only affects CKEditor 5 and all releases currently use CKEditor 4 (2022-03-16)

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.005

Percentile

76.0%