Asymmetric denial of service - ReDoS In ckeditor4-dev
Description
CKEditor 4 ReDoS Vulnerability It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
npm | 4.16 | ||
debian 12 | 4.16.0+dfsg-1 | ||
npm | 4.16 | ||
npm | 4.16.0 | ||
debian 11 | 4.16.0+dfsg-1 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5.