|
| 1 | +--- |
| 2 | +gem: ckeditor |
| 3 | +cve: 2021-37695 |
| 4 | +ghsa: m94c-37g6-cjhc |
| 5 | +url: https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-m94c-37g6-cjhc |
| 6 | +title: Fake objects feature vulnerability allowing to execute JavaScript code using |
| 7 | + malformed HTML. |
| 8 | +date: 2021-08-23 |
| 9 | +description: | |
| 10 | + ### Affected packages |
| 11 | + The vulnerability has been discovered in [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) plugin. All plugins with [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) plugin dependency are affected: |
| 12 | +
|
| 13 | + * [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) |
| 14 | + * [Link](https://ckeditor.com/cke4/addon/link) |
| 15 | + * [Flash](https://ckeditor.com/cke4/addon/flash) |
| 16 | + * [Iframe](https://ckeditor.com/cke4/addon/iframe) |
| 17 | + * [Forms](https://ckeditor.com/cke4/addon/forms) |
| 18 | + * [Page Break](https://ckeditor.com/cke4/addon/pagebreak) |
| 19 | +
|
| 20 | + ### Impact |
| 21 | + A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version < 4.16.2. |
| 22 | +
|
| 23 | + ### Patches |
| 24 | + The problem has been recognized and patched. The fix will be available in version 4.16.2. |
| 25 | +
|
| 26 | + ### For more information |
| 27 | + Email us at security@cksource.com if you have any questions or comments about this advisory. |
| 28 | +
|
| 29 | + ### Acknowledgements |
| 30 | + The CKEditor 4 team would like to thank Mika Kulmala ([kulmik](https://github.com/kulmik)) for recognizing and reporting this vulnerability. |
| 31 | +cvss_v3: 7.3 |
| 32 | +patched_versions: |
| 33 | +- ">= 5.1.2" |
| 34 | +related: |
| 35 | + url: |
| 36 | + - https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-m94c-37g6-cjhc |
| 37 | + - https://nvd.nist.gov/vuln/detail/CVE-2021-37695 |
| 38 | + - https://github.com/ckeditor/ckeditor4/commit/de3c001540715f9c3801aaa38a1917de46cfcf58 |
| 39 | + - https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NYA354LJP47KCVJMTUO77ZCX3ZK42G3T/ |
| 40 | + - https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UVOYN2WKDPLKCNILIGEZM236ABQASLGW/ |
| 41 | + - https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WAGNWHFIQAVCP537KFFS2A2GDG66J7XD/ |
| 42 | + - https://www.oracle.com/security-alerts/cpuoct2021.html |
| 43 | + - https://lists.debian.org/debian-lts-announce/2021/11/msg00007.html |
| 44 | + - https://www.oracle.com/security-alerts/cpujan2022.html |
| 45 | + - https://github.com/advisories/GHSA-m94c-37g6-cjhc |
0 commit comments