CVE-2021-32808
published 2021-08-12CVE-2021-32808: ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside…
PriorityP427medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
1.19%
64.5th percentile
ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version >= 4.13.0. The problem has been recognized and patched. The fix will be available in version 4.16.2.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ckeditor | ckeditor | >= 0 < 4.16.2+dfsg-1 | 4.16.2+dfsg-1 |
| ckeditor | ckeditor | >= 0 < 4.5.7+dfsg-2ubuntu0.18.04.1 | 4.5.7+dfsg-2ubuntu0.18.04.1 |
| ckeditor | ckeditor | >= 0 < 4.12.1+dfsg-1ubuntu0.1 | 4.12.1+dfsg-1ubuntu0.1 |
| ckeditor | ckeditor | >= 0 < 4.5.7+dfsg-2ubuntu0.16.04.1~esm1 | 4.5.7+dfsg-2ubuntu0.16.04.1~esm1 |
| ckeditor | ckeditor | >= 4.13.0 < 4.16.2 | 4.16.2 |
| ckeditor | ckeditor4 | — | — |
| ckeditor | ckeditor4 | >= 4.13.0 < 4.16.2 | 4.16.2 |
| debian | ckeditor | < ckeditor 4.16.2+dfsg-1 (bookworm) | ckeditor 4.16.2+dfsg-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| oracle | application_express | < 21.1.4 | 21.1.4 |
| oracle | banking_party_management | — | — |
| oracle | commerce_guided_search | — | — |
| oracle | commerce_merchandising | — | — |
| oracle | documaker | — | — |
| oracle | documaker | — | — |
| oracle | financial_services_analytical_applications_infrastructure | 8.0.7 – 8.1.1 | — |
| oracle | financial_services_model_management_and_governance | — | — |
| oracle | financial_services_model_management_and_governance | — | — |
| oracle | jd_edwards_enterpriseone_tools | <= 9.2.6.0 | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| oracle | siebel_ui_framework | <= 21.9 | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
ghsa5.4MEDIUM
osv6.1MEDIUM
vendor_debian7.6HIGH
vendor_ubuntu6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
ckeditor vulnerabilities
osv·2022-03-23·CVSS 6.1
CVE-2018-9861 [MEDIUM] ckeditor vulnerabilities
ckeditor vulnerabilities
USN-5340-1 fixed several vulnerabilities in CKEditor.
This update provides the fixes for CVE-2018-9861, CVE-2020-9281,
CVE-2021-32809, CVE-2021-33829 and CVE-2021-37695 for Ubuntu 16.04 ESM.
Original advisory details:
Kyaw Min Thein discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue
to execute arbitrary code. This issue only affects
Ubuntu 18.04 LTS. (CVE-2018-9861)
Micha Bentkowski discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue to
execute arbitrary code. This issue only affects
Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-9281)
Anton Subbotin discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue to
ex
OSV
ckeditor vulnerabilities
osv·2022-03-22·CVSS 6.1
CVE-2018-9861 [MEDIUM] ckeditor vulnerabilities
ckeditor vulnerabilities
Kyaw Min Thein discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue
to execute arbitrary code. This issue only affects
Ubuntu 18.04 LTS. (CVE-2018-9861)
Micha Bentkowski discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue to
execute arbitrary code. This issue only affects
Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-9281)
Anton Subbotin discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue to
execute arbitrary code. This issue only affects
Ubuntu 21.10. (CVE-2021-32808)
Anton Subbotin discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue to
inject arbitrary code
GHSA
CKEditor 4 vulnerabilities in versions <4.16.1
ghsa·2021-08-23·CVSS 5.4
CVE-2021-37695 [MEDIUM] CKEditor 4 vulnerabilities in versions <4.16.1
CKEditor 4 vulnerabilities in versions <4.16.1
Details see:
https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-m94c-37g6-cjhc ( CVE-2021-37695 )
https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-6226-h7ff-ch6c ( CVE-2021-32808 )
https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-7889-rm5j-hpgg ( CVE-2021-32809 )
Patch:
https://github.com/pimcore/pimcore/pull/10032
GHSA
Widget feature vulnerability allowing to execute JavaScript code using undo functionality
ghsa·2021-08-23
CVE-2021-32808 [HIGH] CWE-79 Widget feature vulnerability allowing to execute JavaScript code using undo functionality
Widget feature vulnerability allowing to execute JavaScript code using undo functionality
### Affected packages
The vulnerability has been discovered in [Widget](https://ckeditor.com/cke4/addon/clipboard) plugin if used alongside [Undo](https://ckeditor.com/cke4/addon/undo) feature.
### Impact
A potential vulnerability has been discovered in CKEditor 4 [Widget](https://ckeditor.com/cke4/addon/widget) package. The vulnerability allowed to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version >= 4.13.0.
### Patches
The problem has been recognized and patched. The fix will be available in version 4.16.2.
### For more information
Email us at [email protected] if yo
OSV
Widget feature vulnerability allowing to execute JavaScript code using undo functionality
osv·2021-08-23
CVE-2021-32808 [HIGH] Widget feature vulnerability allowing to execute JavaScript code using undo functionality
Widget feature vulnerability allowing to execute JavaScript code using undo functionality
### Affected packages
The vulnerability has been discovered in [Widget](https://ckeditor.com/cke4/addon/clipboard) plugin if used alongside [Undo](https://ckeditor.com/cke4/addon/undo) feature.
### Impact
A potential vulnerability has been discovered in CKEditor 4 [Widget](https://ckeditor.com/cke4/addon/widget) package. The vulnerability allowed to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version >= 4.13.0.
### Patches
The problem has been recognized and patched. The fix will be available in version 4.16.2.
### For more information
Email us at [email protected] if yo
OSV
CKEditor 4 vulnerabilities in versions <4.16.1
osv·2021-08-23·CVSS 5.4
CVE-2021-37695 [MEDIUM] CKEditor 4 vulnerabilities in versions <4.16.1
CKEditor 4 vulnerabilities in versions <4.16.1
Details see:
https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-m94c-37g6-cjhc ( CVE-2021-37695 )
https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-6226-h7ff-ch6c ( CVE-2021-32808 )
https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-7889-rm5j-hpgg ( CVE-2021-32809 )
Patch:
https://github.com/pimcore/pimcore/pull/10032
OSV
CVE-2021-32808: ckeditor is an open source WYSIWYG HTML editor with rich content support
osv·2021-08-12·CVSS 5.4
CVE-2021-32808 [MEDIUM] CVE-2021-32808: ckeditor is an open source WYSIWYG HTML editor with rich content support
ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version >= 4.13.0. The problem has been recognized and patched. The fix will be available in version 4.16.2.
Ubuntu
CKEditor vulnerabilities
vendor_ubuntu·2022-03-23·CVSS 6.1
CVE-2021-32809 [MEDIUM] CKEditor vulnerabilities
Title: CKEditor vulnerabilities
Summary: Several security issues were fixed in CKEditor.
USN-5340-1 fixed several vulnerabilities in CKEditor.
This update provides the fixes for CVE-2018-9861, CVE-2020-9281,
CVE-2021-32809, CVE-2021-33829 and CVE-2021-37695 for Ubuntu 16.04 ESM.
Original advisory details:
Kyaw Min Thein discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue
to execute arbitrary code. This issue only affects
Ubuntu 18.04 LTS. (CVE-2018-9861)
Micha Bentkowski discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue to
execute arbitrary code. This issue only affects
Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-9281)
Anton Subbotin discovered that CKEditor incorrectly handle
Ubuntu
CKEditor vulnerabilities
vendor_ubuntu·2022-03-22·CVSS 6.1
CVE-2020-9281 [MEDIUM] CKEditor vulnerabilities
Title: CKEditor vulnerabilities
Summary: Several security issues were fixed in CKEditor.
Kyaw Min Thein discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue
to execute arbitrary code. This issue only affects
Ubuntu 18.04 LTS. (CVE-2018-9861)
Micha Bentkowski discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue to
execute arbitrary code. This issue only affects
Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-9281)
Anton Subbotin discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue to
execute arbitrary code. This issue only affects
Ubuntu 21.10. (CVE-2021-32808)
Anton Subbotin discovered that CKEditor incorrectly handled
certain inputs. A
Debian
CVE-2021-32808: ckeditor - ckeditor is an open source WYSIWYG HTML editor with rich content support. A vuln...
vendor_debian·2021·CVSS 7.6
CVE-2021-32808 [HIGH] CVE-2021-32808: ckeditor - ckeditor is an open source WYSIWYG HTML editor with rich content support. A vuln...
ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version >= 4.13.0. The problem has been recognized and patched. The fix will be available in version 4.16.2.
Scope: local
bookworm: resolved (fixed in 4.16.2+dfsg-1)
bullseye: open
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/ckeditor/ckeditor4/releases/tag/4.16.2https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-6226-h7ff-ch6chttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NYA354LJP47KCVJMTUO77ZCX3ZK42G3T/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UVOYN2WKDPLKCNILIGEZM236ABQASLGW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WAGNWHFIQAVCP537KFFS2A2GDG66J7XD/https://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://github.com/ckeditor/ckeditor4/releases/tag/4.16.2https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-6226-h7ff-ch6chttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NYA354LJP47KCVJMTUO77ZCX3ZK42G3T/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UVOYN2WKDPLKCNILIGEZM236ABQASLGW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WAGNWHFIQAVCP537KFFS2A2GDG66J7XD/https://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2021-08-12
Published