First published: Thu Aug 12 2021(Updated: )
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version < 4.16.2. The problem has been recognized and patched. The fix will be available in version 4.16.2.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ckeditor Ckeditor | <4.16.2 | |
Debian Debian Linux | =9.0 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 | |
Fedoraproject Fedora | =35 | |
Oracle Application Express | <21.1.4 | |
Oracle Banking Party Management | =2.7.0 | |
Oracle Commerce Guided Search | =11.3.2 | |
Oracle Commerce Merchandising | =11.3.2 | |
Oracle Documaker | =12.6.3 | |
Oracle Documaker | =12.6.4 | |
Oracle Financial Services Analytical Applications Infrastructure | >=8.0.7<=8.1.1 | |
Oracle Financial Services Analytical Applications Infrastructure | =8.0.3 | |
Oracle Financial Services Model Management And Governance | >=8.0.8.0.0<=8.1.0.0.0 | |
Oracle Jd Edwards Enterpriseone Tools | <9.2.6.0 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.57 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.58 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.59 | |
IBM IBM® Engineering Requirements Management DOORS | <=9.7.2.7 | |
IBM IBM® Engineering Requirements Management DOORS Web Access | <=9.7.2.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-37695.
CKEditor is an open source WYSIWYG HTML editor with rich content support.
The severity of CVE-2021-37695 is high with a CVSS score of 5.4.
CVE-2021-37695 allows the injection of malformed Fake Objects HTML, which could result in executing arbitrary code.
To fix CVE-2021-37695, upgrade to CKEditor version 4.16.3 or later.