CVE-2021-32808 – ckeditor4
Package
Manager: npm
Name: ckeditor4
Vulnerable Version: >=4.13.0 <4.16.2
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS: 0.01222 pctl0.78336
Details
Widget feature vulnerability allowing to execute JavaScript code using undo functionality ### Affected packages The vulnerability has been discovered in [Widget](https://ckeditor.com/cke4/addon/clipboard) plugin if used alongside [Undo](https://ckeditor.com/cke4/addon/undo) feature. ### Impact A potential vulnerability has been discovered in CKEditor 4 [Widget](https://ckeditor.com/cke4/addon/widget) package. The vulnerability allowed to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version >= 4.13.0. ### Patches The problem has been recognized and patched. The fix will be available in version 4.16.2. ### For more information Email us at security@cksource.com if you have any questions or comments about this advisory. ### Acknowledgements The CKEditor 4 team would like to thank Anton Subbotin ([skavans](https://github.com/skavans)) for recognizing and reporting this vulnerability.
Metadata
Created: 2021-08-23T19:40:48Z
Modified: 2022-02-08T21:01:57Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/08/GHSA-6226-h7ff-ch6c/GHSA-6226-h7ff-ch6c.json
CWE IDs: ["CWE-79"]
Alternative ID: GHSA-6226-h7ff-ch6c
Finding: F008
Auto approve: 1