Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-48110
HistoryFeb 13, 2023 - 12:00 a.m.

CVE-2022-48110

2023-02-1300:00:00
ubuntu.com
ubuntu.com
11
cksource ckeditor 5
xss
cross-site scripting
full featured ckeditor5
security settings

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

0.001 Low

EPSS

Percentile

37.2%

DISPUTED CKSource CKEditor 5 35.4.0 was discovered to contain a
cross-site scripting (XSS) vulnerability via the Full Featured CKEditor5
widget. NOTE: the vendor’s position is that this is not a vulnerability.
The CKEditor 5 documentation discusses that it is the responsibility of an
integrator (who is adding CKEditor 5 functionality to a website) to choose
the correct security settings for their use case. Also, safe default values
are established (e.g., config.htmlEmbed.showPreviews is false).

Notes

Author Note
sbeattie embedded copies of ckeditor are in ldap-account-manager, rt4, and rt5

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

0.001 Low

EPSS

Percentile

37.2%