First published: Tue May 25 2021(Updated: )
A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/drupal/drupal | >=7.0.0<7.80>=8.0.0<8.1.0>=8.1.0<8.2.0>=8.2.0<8.3.0>=8.3.0<8.4.0>=8.4.0<8.5.0>=8.5.0<8.6.0>=8.6.0<8.7.0>=8.7.0<8.8.0>=8.8.0<8.9.0>=8.9.0<8.9.16>=9.0.0<9.0.14>=9.1.0<9.1.9 | |
composer/drupal/core | >=7.0.0<7.80>=8.0.0<8.1.0>=8.1.0<8.2.0>=8.2.0<8.3.0>=8.3.0<8.4.0>=8.4.0<8.5.0>=8.5.0<8.6.0>=8.6.0<8.7.0>=8.7.0<8.8.0>=8.8.0<8.9.0>=8.9.0<8.9.16>=9.0.0<9.0.14>=9.1.0<9.1.9 | |
Ckeditor Ckeditor | >=4.14.0<4.16.1 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 | |
Fedoraproject Fedora | =35 | |
Drupal Drupal | >=8.9.0<8.9.16 | |
Drupal Drupal | >=9.0.0<9.0.14 | |
Drupal Drupal | >=9.1.0<9.1.9 | |
Debian Debian Linux | =9.0 | |
composer/drupal/drupal | >=9.1.0<9.1.9 | 9.1.9 |
composer/drupal/drupal | >=9.0.0<9.0.14 | 9.0.14 |
composer/drupal/drupal | >=8.0.0<8.9.16 | 8.9.16 |
composer/drupal/drupal | >=7.0.0<7.80 | 7.80 |
composer/drupal/core | >=9.1.0<9.1.9 | 9.1.9 |
composer/drupal/core | >=9.0.0<9.0.14 | 9.0.14 |
composer/drupal/core | >=8.0.0<8.9.16 | 8.9.16 |
composer/drupal/core | >=7.0.0<7.80 | 7.80 |
npm/ckeditor4 | >=4.14.0<4.16.1 | 4.16.1 |
IBM IBM® Engineering Requirements Management DOORS | <=9.7.2.7 | |
IBM IBM® Engineering Requirements Management DOORS Web Access | <=9.7.2.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-33829 is a vulnerability in Drupal core that allows for cross-site scripting (XSS) attacks.
CVE-2021-33829 has a severity rating of 7.2, which is considered high.
CVE-2021-33829 can allow remote attackers to inject malicious scripts into a Drupal website, which can be executed by visitors to the site, compromising their browsing security.
Versions 7.x, 8.x, and 9.x of Drupal are affected by CVE-2021-33829.
For more information about CVE-2021-33829 and its remediation, you can visit the Drupal Security Advisory SA-CORE-2021-003 or the IBM X-Force Exchange website.