CVE-2021-41164
published 2021-11-17CVE-2021-41164: CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may…
PriorityP426medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
1.26%
66.2th percentile
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ckeditor | ckeditor | >= 0 < 4.19.0+dfsg-1 | 4.19.0+dfsg-1 |
| ckeditor | ckeditor | >= 4.0 < 4.17.0 | 4.17.0 |
| ckeditor | ckeditor4 | < 4.17.0 | 4.17.0 |
| ckeditor | ckeditor4 | >= 0 < 4.17.0 | 4.17.0 |
| debian | ckeditor | < ckeditor 4.19.0+dfsg-1 (bookworm) | ckeditor 4.19.0+dfsg-1 (bookworm) |
| debian | ckeditor3 | < ckeditor 4.19.0+dfsg-1 (bookworm) | ckeditor 4.19.0+dfsg-1 (bookworm) |
| drupal | core | >= 8.0.0 < 8.9.20 | 8.9.20 |
| drupal | core | >= 9.1.0 < 9.1.14 | 9.1.14 |
| drupal | core | >= 9.2.0 < 9.2.9 | 9.2.9 |
| drupal | drupal | >= 8.9.0 < 8.9.20 | 8.9.20 |
| drupal | drupal | >= 9.1.0 < 9.1.14 | 9.1.14 |
| drupal | drupal | >= 9.2.0 < 9.2.9 | 9.2.9 |
| drupal | drupal_core | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| oracle | agile_plm | — | — |
| oracle | application_express | < 22.1 | 22.1 |
| oracle | banking_apis | — | — |
| oracle | banking_apis | — | — |
| oracle | banking_apis | — | — |
| oracle | banking_apis | — | — |
| oracle | banking_apis | 18.1 – 18.3 | — |
| oracle | banking_digital_experience | — | — |
| oracle | banking_digital_experience | — | — |
| oracle | banking_digital_experience | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv5.4MEDIUM
vendor_debian8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Drupal
Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2021-011
vendor_drupal·2021-11-17·CVSS 8.2
CVE-2021-41165 [HIGH] Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2021-011
Title: Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2021-011
Vulnerability Type: Cross Site Scripting
Description: The Drupal project uses the CKEditor library for WYSIWYG editing. CKEditor has released a security update that impacts Drupal , along with a hotfix for that update . Vulnerabilities are possible if Drupal is configured to allow use of the CKEditor library for WYSIWYG editing. An attacker that can create or edit content (even without access to CKEditor themselves) may be able to exploit one or more Cross-Site Scripting (XSS) vulnerabilities to target users with access to the WYSIWYG CKEditor, including site admins with privileged access. For more information, see CKEditor's security advisories: CVE-2021-41165: HTML comments vulnerability allowing to exec
Debian
CVE-2021-41164: ckeditor - CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerab...
vendor_debian·2021·CVSS 8.2
CVE-2021-41164 [HIGH] CVE-2021-41164: ckeditor - CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerab...
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.
Scope: local
bookworm: resolved (fixed in 4.19.0+dfsg-1)
bullseye: open
GHSA
Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTML
ghsa·2021-11-17
CVE-2021-41164 [HIGH] CWE-79 Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTML
Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTML
### Affected packages
The vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4.
### Impact
A potential vulnerability has been discovered in CKEditor 4 Advanced Content Filter (ACF) core module. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0.
### Patches
The problem has been recognized and patched. The fix will be available in version 4.17.0.
### For more information
Email us at [email protected] if you have any questions or comments about this advisory.
### Acknowledg
OSV
The Drupal project uses the [CKEditor](https://github
osv·2021-11-17·CVSS 5.4
[MEDIUM] The Drupal project uses the [CKEditor](https://github
The Drupal project uses the [CKEditor](https://github.com/ckeditor/ckeditor4) library for WYSIWYG editing. CKEditor has released [a security update that impacts Drupal](https://ckeditor.com/cke4/release/CKEditor-4.17.0), along with a [hotfix for that update](https://ckeditor.com/cke4/release/CKEditor-4.17.1).
Vulnerabilities are possible if Drupal is configured to allow use of the CKEditor library for WYSIWYG editing. An attacker that can create or edit content (even without access to CKEditor themselves) may be able to exploit one or more Cross-Site Scripting (XSS) vulnerabilities to target users with access to the WYSIWYG CKEditor, including site admins with privileged access.
For more information, see CKEditor's security advisories:
* [CVE-2021-41165: HTML comments vulnerability allo
OSV
CVE-2021-41164: CKEditor4 is an open source WYSIWYG HTML editor
osv·2021-11-17·CVSS 5.4
CVE-2021-41164 [MEDIUM] CVE-2021-41164: CKEditor4 is an open source WYSIWYG HTML editor
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.
OSV
Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTML
osv·2021-11-17
CVE-2021-41164 [HIGH] Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTML
Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTML
### Affected packages
The vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4.
### Impact
A potential vulnerability has been discovered in CKEditor 4 Advanced Content Filter (ACF) core module. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0.
### Patches
The problem has been recognized and patched. The fix will be available in version 4.17.0.
### For more information
Email us at [email protected] if you have any questions or comments about this advisory.
### Acknowledg
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/ckeditor/ckeditor4/blob/major/CHANGES.md#ckeditor-417https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-pvmx-g8h5-cprjhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VR76VBN5GW5QUBJFHVXRX36UZ6YTCMW6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WOZGMCYDB2OKKULFXZKM6V7JJW4ZZHJP/https://www.drupal.org/sa-core-2021-011https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://github.com/ckeditor/ckeditor4/blob/major/CHANGES.md#ckeditor-417https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-pvmx-g8h5-cprjhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VR76VBN5GW5QUBJFHVXRX36UZ6YTCMW6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WOZGMCYDB2OKKULFXZKM6V7JJW4ZZHJP/https://www.drupal.org/sa-core-2021-011https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.html
2021-11-17
Published