cbcvebase.
CVE-2021-26272
published 2021-01-26

CVE-2021-26272: It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then…

medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).

Affected

21 ranges
VendorProductVersion rangeFixed in
ckeditorckeditor>= 0 < 4.16.0+dfsg-14.16.0+dfsg-1
ckeditorckeditor>= 0 < 4.16.0+dfsg-14.16.0+dfsg-1
ckeditorckeditor>= 4.0 < 4.164.16
ckeditorckeditor4>= 0 < 4.16.04.16.0
debianckeditor< ckeditor 4.16.0+dfsg-1 (bookworm)ckeditor 4.16.0+dfsg-1 (bookworm)
debianckeditor3< ckeditor 4.16.0+dfsg-1 (bookworm)ckeditor 4.16.0+dfsg-1 (bookworm)
oracleagile_plm
oracleagile_plm
oracleapplication_express< 21.1.021.1.0
oraclebanking_party_management
oraclecommerce_merchandising
oraclecommerce_merchandising
oraclecommerce_merchandising11.3.0 – 11.3.2
oraclefinancial_services_analytical_applications_infrastructure
oraclefinancial_services_analytical_applications_infrastructure
oraclefinancial_services_analytical_applications_infrastructure8.0.6 – 8.0.9
oraclefinancial_services_model_management_and_governance8.0.8.0.0 – 8.1.0.0.0
oraclejd_edwards_enterpriseone_tools< 9.2.6.09.2.6.0
oraclesiebel_ui_framework<= 21.9
oraclewebcenter_sites
oraclewebcenter_sites

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM