cbcvebase.
CVE-2021-26271
published 2021-01-26

CVE-2021-26271: It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific…

medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).

Affected

15 ranges
VendorProductVersion rangeFixed in
ckeditorckeditor>= 0 < 4.16.0+dfsg-14.16.0+dfsg-1
ckeditorckeditor>= 0 < 4.16.0+dfsg-14.16.0+dfsg-1
ckeditorckeditor>= 4.0 < 4.164.16
debianckeditor< ckeditor 4.16.0+dfsg-1 (bookworm)ckeditor 4.16.0+dfsg-1 (bookworm)
debianckeditor3< ckeditor 4.16.0+dfsg-1 (bookworm)ckeditor 4.16.0+dfsg-1 (bookworm)
oracleagile_plm
oracleagile_plm
oracleapplication_express< 21.1.021.1.0
oraclefinancial_services_analytical_applications_infrastructure
oraclefinancial_services_analytical_applications_infrastructure
oraclefinancial_services_analytical_applications_infrastructure8.0.6 – 8.0.9
oraclejd_edwards_enterpriseone_tools< 9.2.6.09.2.6.0
oraclesiebel_ui_framework< 21.921.9
oraclewebcenter_sites
oraclewebcenter_sites

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM