Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29151
HistoryJan 27, 2021 - 5:34 a.m.

Regular Expression Denial Of Service (ReDoS)

2021-01-2705:34:12
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5

0.002 Low

EPSS

Percentile

53.2%

ckeditor4 is vulnerable to regular expression denial of service. An insecure usage of the regular expression allows an attacker to crash the user’s browser through excessive memory consumption by tricking a user into pasting a malicious text into nto the editor, and then press Enter or Space (in the Autolink plugin).