CVE-2021-26271
published 2021-01-26CVE-2021-26271: It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific…
PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
1.96%
78.1th percentile
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ckeditor | ckeditor | >= 0 < 4.16.0+dfsg-1 | 4.16.0+dfsg-1 |
| ckeditor | ckeditor | >= 0 < 4.16.0+dfsg-1 | 4.16.0+dfsg-1 |
| ckeditor | ckeditor | >= 4.0 < 4.16 | 4.16 |
| debian | ckeditor | < ckeditor 4.16.0+dfsg-1 (bookworm) | ckeditor 4.16.0+dfsg-1 (bookworm) |
| debian | ckeditor3 | < ckeditor 4.16.0+dfsg-1 (bookworm) | ckeditor 4.16.0+dfsg-1 (bookworm) |
| oracle | agile_plm | — | — |
| oracle | agile_plm | — | — |
| oracle | application_express | < 21.1.0 | 21.1.0 |
| oracle | financial_services_analytical_applications_infrastructure | — | — |
| oracle | financial_services_analytical_applications_infrastructure | — | — |
| oracle | financial_services_analytical_applications_infrastructure | 8.0.6 – 8.0.9 | — |
| oracle | jd_edwards_enterpriseone_tools | < 9.2.6.0 | 9.2.6.0 |
| oracle | siebel_ui_framework | < 21.9 | 21.9 |
| oracle | webcenter_sites | — | — |
| oracle | webcenter_sites | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
CKEditor 4 ReDoS Vulnerability
ghsa·2022-05-24
CVE-2021-26271 [MEDIUM] CWE-1333 CKEditor 4 ReDoS Vulnerability
CKEditor 4 ReDoS Vulnerability
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
OSV
CKEditor 4 ReDoS Vulnerability
osv·2022-05-24
CVE-2021-26271 [MEDIUM] CKEditor 4 ReDoS Vulnerability
CKEditor 4 ReDoS Vulnerability
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
OSV
CVE-2021-26271: It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4
osv·2021-01-26·CVSS 6.5
CVE-2021-26271 [MEDIUM] CVE-2021-26271: It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
Debian
CVE-2021-26271: ckeditor - It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by ...
vendor_debian·2021·CVSS 6.5
CVE-2021-26271 [MEDIUM] CVE-2021-26271: ckeditor - It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by ...
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
Scope: local
bookworm: resolved (fixed in 4.16.0+dfsg-1)
bullseye: resolved (fixed in 4.16.0+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://ckeditor.com/blog/CKEditor-4.16-with-improved-image-pasting-High-Contrast-support-and-a-new-color-API/#security-comes-firsthttps://github.com/ckeditor/ckeditor4/blob/major/CHANGES.md#ckeditor-416https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://ckeditor.com/blog/CKEditor-4.16-with-improved-image-pasting-High-Contrast-support-and-a-new-color-API/#security-comes-firsthttps://github.com/ckeditor/ckeditor4/blob/major/CHANGES.md#ckeditor-416https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2021-01-26
Published