CVE-2021-26272
published 2021-01-26CVE-2021-26272: It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then…
PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
2.22%
80.7th percentile
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ckeditor | ckeditor | >= 0 < 4.16.0+dfsg-1 | 4.16.0+dfsg-1 |
| ckeditor | ckeditor | >= 0 < 4.16.0+dfsg-1 | 4.16.0+dfsg-1 |
| ckeditor | ckeditor | >= 4.0 < 4.16 | 4.16 |
| ckeditor | ckeditor4 | >= 0 < 4.16.0 | 4.16.0 |
| debian | ckeditor | < ckeditor 4.16.0+dfsg-1 (bookworm) | ckeditor 4.16.0+dfsg-1 (bookworm) |
| debian | ckeditor3 | < ckeditor 4.16.0+dfsg-1 (bookworm) | ckeditor 4.16.0+dfsg-1 (bookworm) |
| oracle | agile_plm | — | — |
| oracle | agile_plm | — | — |
| oracle | application_express | < 21.1.0 | 21.1.0 |
| oracle | banking_party_management | — | — |
| oracle | commerce_merchandising | — | — |
| oracle | commerce_merchandising | — | — |
| oracle | commerce_merchandising | 11.3.0 – 11.3.2 | — |
| oracle | financial_services_analytical_applications_infrastructure | — | — |
| oracle | financial_services_analytical_applications_infrastructure | — | — |
| oracle | financial_services_analytical_applications_infrastructure | 8.0.6 – 8.0.9 | — |
| oracle | financial_services_model_management_and_governance | 8.0.8.0.0 – 8.1.0.0.0 | — |
| oracle | jd_edwards_enterpriseone_tools | < 9.2.6.0 | 9.2.6.0 |
| oracle | siebel_ui_framework | <= 21.9 | — |
| oracle | webcenter_sites | — | — |
| oracle | webcenter_sites | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_oracle6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Inclusion of Functionality from Untrusted Control Sphere in CKEditor 4
ghsa·2021-10-13
CVE-2021-26272 [MEDIUM] CWE-829 Inclusion of Functionality from Untrusted Control Sphere in CKEditor 4
Inclusion of Functionality from Untrusted Control Sphere in CKEditor 4
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
OSV
Inclusion of Functionality from Untrusted Control Sphere in CKEditor 4
osv·2021-10-13
CVE-2021-26272 [MEDIUM] Inclusion of Functionality from Untrusted Control Sphere in CKEditor 4
Inclusion of Functionality from Untrusted Control Sphere in CKEditor 4
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
OSV
CVE-2021-26272: It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4
osv·2021-01-26·CVSS 6.5
CVE-2021-26272 [MEDIUM] CVE-2021-26272: It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
Oracle
Oracle Oracle Database Server Risk Matrix: Oracle Application Express (CKEditor) — CVE-2021-26272
vendor_oracle·2021-10-15·CVSS 4.3
CVE-2021-26272 [MEDIUM] Oracle Oracle Database Server Risk Matrix: Oracle Application Express (CKEditor) — CVE-2021-26272
Oracle Oracle Database Server Risk Matrix: Oracle Application Express (CKEditor) vulnerability
CVE: CVE-2021-26272
CVSS: 4.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Oracle
Oracle Oracle Commerce Risk Matrix: Experience Manager, Business Control Center (CKEditor) — CVE-2021-26272
vendor_oracle·2021-07-15·CVSS 6.5
CVE-2021-26272 [MEDIUM] Oracle Oracle Commerce Risk Matrix: Experience Manager, Business Control Center (CKEditor) — CVE-2021-26272
Oracle Oracle Commerce Risk Matrix: Experience Manager, Business Control Center (CKEditor) vulnerability
CVE: CVE-2021-26272
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Debian
CVE-2021-26272: ckeditor - It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by ...
vendor_debian·2021·CVSS 6.5
CVE-2021-26272 [MEDIUM] CVE-2021-26272: ckeditor - It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by ...
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
Scope: local
bookworm: resolved (fixed in 4.16.0+dfsg-1)
bullseye: resolved (fixed in 4.16.0+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://ckeditor.com/blog/CKEditor-4.16-with-improved-image-pasting-High-Contrast-support-and-a-new-color-API/#security-comes-firsthttps://github.com/ckeditor/ckeditor4/blob/major/CHANGES.md#ckeditor-416https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://ckeditor.com/blog/CKEditor-4.16-with-improved-image-pasting-High-Contrast-support-and-a-new-color-API/#security-comes-firsthttps://github.com/ckeditor/ckeditor4/blob/major/CHANGES.md#ckeditor-416https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2021-01-26
Published