RubySec

Providing security resources for the Ruby community

CVE-2021-26272 (ckeditor): Inclusion of Functionality from Untrusted Control Sphere in CKEditor 4

Inclusion of Functionality from Untrusted Control Sphere in CKEditor 4

Published: October 13, 2021

SECURITY IDENTIFIERS

GEM

ckeditor

SEVERITY

CVSS v3.x: 6.5 (Medium)

PATCHED VERSIONS

>= 5.1.2

DESCRIPTION

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).

RELATED