First published: Wed Feb 07 2024(Updated: )
### Affected packages The vulnerability has been discovered in the samples that use the [preview](https://ckeditor.com/cke4/addon/preview) feature: * `samples/old/**/*.html` * `plugins/[plugin name]/samples/**/*.html` All integrators that use these samples in the production code can be affected. ### Impact A potential vulnerability has been discovered in one of CKEditor's 4 samples that are shipped with production code. The vulnerability allowed to execute JavaScript code by abusing the misconfigured [preview feature](https://ckeditor.com/cke4/addon/preview). It affects all users using the CKEditor 4 at version < 4.24.0-lts with affected samples used in a production environment. ### Patches The problem has been recognized and patched. The fix will be available in version 4.24.0-lts. ### For more information Email us at [security@cksource.com](mailto:security@cksource.com) if you have any questions or comments about this advisory. ### Acknowledgements The CKEditor 4 team would like to thank [Marcin Wyczechowski](https://www.linkedin.com/in/marcin-wyczechowski-0a823795/) & [Michał Majchrowicz](https://www.linkedin.com/in/micha%C5%82-majchrowicz-mwsc/) [AFINE Team](https://afine.com/) for recognizing and reporting this vulnerability.
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
npm/ckeditor4 | <4.24.0-lts | 4.24.0-lts |
debian/ckeditor | <=4.16.0+dfsg-2<=4.19.1+dfsg-1<=4.22.1+dfsg1-2 | |
debian/ckeditor3 | <=3.6.6.1+dfsg-7 | |
CKEditor | >=4.0<4.24.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-24816 has a medium severity rating due to potential security compromises in applications using specific CKEditor 4 samples.
To fix CVE-2024-24816, upgrade CKEditor to version 4.24.0-lts or later.
CVE-2024-24816 affects all CKEditor versions from 4.0 up to, but not including, 4.24.0.
CVE-2024-24816 impacts the preview feature in CKEditor 4 when using specific sample files.
The specific package to update for CVE-2024-24816 is the ckeditor4 package.