Skip to content

Commit

Permalink
[SECURITY] Update library CKEditor to 4.11.1
Browse files Browse the repository at this point in the history
CKEditor 4.11 was released including a XSS fix where
an attacker could add invalid HTML markup by switching
to the Source mode of CKEditor and back.

Used commands:
  cd Build/
  yarn add ckeditor#4.11.1 --dev
  grunt build

Resolves: #84800
Releases: master, 8.7
Security-Commit: 4a44c536a4f80b1fbf4599070761368e7919980c
Security-Bulletin: TYPO3-CORE-SA-2018-005
Change-Id: I50412f24393c306a989dac448d7c0ee66a6760fb
Reviewed-on: https://review.typo3.org/59099
Reviewed-by: Oliver Hader <oliver.hader@typo3.org>
Tested-by: Oliver Hader <oliver.hader@typo3.org>
  • Loading branch information
bmack authored and ohader committed Dec 11, 2018
1 parent 412666d commit 6959fc7
Show file tree
Hide file tree
Showing 216 changed files with 1,644 additions and 1,351 deletions.
2 changes: 1 addition & 1 deletion Build/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@
"bootstrap-sass": "^3.3.7",
"bootstrap-slider": "^9.7.3",
"chosen-js": "^1.7.0",
"ckeditor": "4.10.1",
"ckeditor": "^4.11.1",
"ckeditor-wordcount-plugin": "^1.17.2",
"codemirror": "^5.40.0",
"cropper": "^2.3.4",
Expand Down
8 changes: 4 additions & 4 deletions Build/yarn.lock
Original file line number Diff line number Diff line change
Expand Up @@ -1071,10 +1071,10 @@ ckeditor-wordcount-plugin@^1.17.2:
resolved "https://registry.yarnpkg.com/ckeditor-wordcount-plugin/-/ckeditor-wordcount-plugin-1.17.2.tgz#9bd528bcf3f2898948fc056d8fdbe80106e87381"
integrity sha512-CAS64xhKCQJE3TGIFQECBIrGNFp4neFRdhB4JQ5DiCvnZ36VXd7UydJm6UiIBXZEUag9ykdBe4n5anYIkG6sNA==

ckeditor@4.10.1:
version "4.10.1"
resolved "https://registry.yarnpkg.com/ckeditor/-/ckeditor-4.10.1.tgz#e0230b05a5470ef070be9ab9ba444fea418ebc78"
integrity sha512-T6y4BH9ml+0F1cuSqjOWSZJtNuunVm/IbZl0KWNgRUsWEiwQQxhzA0mvSVLzujjsQkTMn9oTGcDd31/eozCAWg==
ckeditor@^4.11.1:
version "4.11.1"
resolved "https://registry.yarnpkg.com/ckeditor/-/ckeditor-4.11.1.tgz#ace84b209573abf2b8430c214500e68ab06e7a14"
integrity sha512-UhHe02cc/wWJquDQZysEgh0ohLMEMU56zDx+s8prDdjylY/aBDY2xdIiIpbgCBTXdjhrEPIAPyiDS9g3RxYXig==

clap@^1.0.9:
version "1.2.3"
Expand Down
1,889 changes: 948 additions & 941 deletions typo3/sysext/rte_ckeditor/Resources/Public/JavaScript/Contrib/ckeditor.js

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Large diffs are not rendered by default.

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

0 comments on commit 6959fc7

Please sign in to comment.