CVE-2021-41165
published 2021-11-17CVE-2021-41165: CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all…
PriorityP427medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
1.47%
70.8th percentile
CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ckeditor | ckeditor | < 4.17.0 | 4.17.0 |
| ckeditor | ckeditor | >= 0 < 4.19.0+dfsg-1 | 4.19.0+dfsg-1 |
| ckeditor | ckeditor | >= 0 < 4.17.0 | 4.17.0 |
| ckeditor | ckeditor4 | < 4.17.0 | 4.17.0 |
| ckeditor | ckeditor4 | >= 0 < 4.17.0 | 4.17.0 |
| debian | ckeditor | < ckeditor 4.19.0+dfsg-1 (bookworm) | ckeditor 4.19.0+dfsg-1 (bookworm) |
| debian | ckeditor3 | < ckeditor 4.19.0+dfsg-1 (bookworm) | ckeditor 4.19.0+dfsg-1 (bookworm) |
| drupal | core | >= 8.0.0 < 8.9.20 | 8.9.20 |
| drupal | core | >= 9.1.0 < 9.1.14 | 9.1.14 |
| drupal | core | >= 9.2.0 < 9.2.9 | 9.2.9 |
| drupal | drupal | >= 8.9.0 < 8.9.20 | 8.9.20 |
| drupal | drupal | >= 9.1.0 < 9.1.14 | 9.1.14 |
| drupal | drupal | >= 9.2.0 < 9.2.9 | 9.2.9 |
| drupal | drupal_core | — | — |
| oracle | agile_product_lifecycle_management | — | — |
| oracle | application_express | < 22.1 | 22.1 |
| oracle | banking_apis | — | — |
| oracle | banking_apis | — | — |
| oracle | banking_apis | — | — |
| oracle | banking_apis | — | — |
| oracle | banking_apis | 18.1 – 18.3 | — |
| oracle | banking_digital_experience | — | — |
| oracle | banking_digital_experience | — | — |
| oracle | banking_digital_experience | — | — |
| oracle | banking_digital_experience | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv5.4MEDIUM
vendor_debian8.2HIGH
vendor_oracle5.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
HTML comments vulnerability allowing to execute JavaScript code
ghsa·2021-11-17
CVE-2021-41165 [HIGH] CWE-79 HTML comments vulnerability allowing to execute JavaScript code
HTML comments vulnerability allowing to execute JavaScript code
### Affected packages
The vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4.
### Impact
A potential vulnerability has been discovered in CKEditor 4 HTML processing core module. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0.
### Patches
The problem has been recognized and patched. The fix will be available in version 4.17.0.
### For more information
Email us at [email protected] if you have any questions or comments about this advisory.
### Acknowledgements
The CKEditor 4 team would like to thank Will
OSV
HTML comments vulnerability allowing to execute JavaScript code
osv·2021-11-17
CVE-2021-41165 [HIGH] HTML comments vulnerability allowing to execute JavaScript code
HTML comments vulnerability allowing to execute JavaScript code
### Affected packages
The vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4.
### Impact
A potential vulnerability has been discovered in CKEditor 4 HTML processing core module. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0.
### Patches
The problem has been recognized and patched. The fix will be available in version 4.17.0.
### For more information
Email us at [email protected] if you have any questions or comments about this advisory.
### Acknowledgements
The CKEditor 4 team would like to thank Will
OSV
The Drupal project uses the [CKEditor](https://github
osv·2021-11-17·CVSS 5.4
[MEDIUM] The Drupal project uses the [CKEditor](https://github
The Drupal project uses the [CKEditor](https://github.com/ckeditor/ckeditor4) library for WYSIWYG editing. CKEditor has released [a security update that impacts Drupal](https://ckeditor.com/cke4/release/CKEditor-4.17.0), along with a [hotfix for that update](https://ckeditor.com/cke4/release/CKEditor-4.17.1).
Vulnerabilities are possible if Drupal is configured to allow use of the CKEditor library for WYSIWYG editing. An attacker that can create or edit content (even without access to CKEditor themselves) may be able to exploit one or more Cross-Site Scripting (XSS) vulnerabilities to target users with access to the WYSIWYG CKEditor, including site admins with privileged access.
For more information, see CKEditor's security advisories:
* [CVE-2021-41165: HTML comments vulnerability allo
OSV
CVE-2021-41165: CKEditor4 is an open source WYSIWYG HTML editor
osv·2021-11-17·CVSS 5.4
CVE-2021-41165 [MEDIUM] CVE-2021-41165: CKEditor4 is an open source WYSIWYG HTML editor
CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: UI (CKEditor) — CVE-2021-41165
vendor_oracle·2023-10-15·CVSS 5.4
CVE-2021-41165 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: UI (CKEditor) — CVE-2021-41165
Oracle Oracle Financial Services Applications Risk Matrix: UI (CKEditor) vulnerability
CVE: CVE-2021-41165
CVSS: 5.4
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2023 (OCT 2023)
Oracle
Oracle Oracle Database Server Risk Matrix: Oracle Application Express (CKEditor) — CVE-2021-41165
vendor_oracle·2022-04-15·CVSS 5.4
CVE-2021-41165 [HIGH] Oracle Oracle Database Server Risk Matrix: Oracle Application Express (CKEditor) — CVE-2021-41165
Oracle Oracle Database Server Risk Matrix: Oracle Application Express (CKEditor) vulnerability
CVE: CVE-2021-41165
CVSS: 5.4
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Framework (CKEditor) — CVE-2021-41165
vendor_oracle·2022-01-15·CVSS 5.4
CVE-2021-41165 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Framework (CKEditor) — CVE-2021-41165
Oracle Oracle Financial Services Applications Risk Matrix: Framework (CKEditor) vulnerability
CVE: CVE-2021-41165
CVSS: 5.4
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Drupal
Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2021-011
vendor_drupal·2021-11-17·CVSS 8.2
CVE-2021-41165 [HIGH] Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2021-011
Title: Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2021-011
Vulnerability Type: Cross Site Scripting
Description: The Drupal project uses the CKEditor library for WYSIWYG editing. CKEditor has released a security update that impacts Drupal , along with a hotfix for that update . Vulnerabilities are possible if Drupal is configured to allow use of the CKEditor library for WYSIWYG editing. An attacker that can create or edit content (even without access to CKEditor themselves) may be able to exploit one or more Cross-Site Scripting (XSS) vulnerabilities to target users with access to the WYSIWYG CKEditor, including site admins with privileged access. For more information, see CKEditor's security advisories: CVE-2021-41165: HTML comments vulnerability allowing to exec
Debian
CVE-2021-41165: ckeditor - CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerabi...
vendor_debian·2021·CVSS 8.2
CVE-2021-41165 [HIGH] CVE-2021-41165: ckeditor - CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerabi...
CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.
Scope: local
bookworm: resolved (fixed in 4.19.0+dfsg-1)
bullseye: open
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/ckeditor/ckeditor4/blob/major/CHANGES.md#ckeditor-417https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-7h26-63m7-qhf2https://www.drupal.org/sa-core-2021-011https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://github.com/ckeditor/ckeditor4/blob/major/CHANGES.md#ckeditor-417https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-7h26-63m7-qhf2https://www.drupal.org/sa-core-2021-011https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.html
2021-11-17
Published