ZeroHour

CVE-2022-24729

CVSS 3.1
7.5 high
EPSS
2%p84
Published
()
Modified
Description

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop resulting in a browser tab freeze. A patch is available in version 4.18.0. There are currently no known workarounds.

Vendors
ckeditordrupaloraclefedoraproject
Products
ckeditor, drupal, application express, commerce merchandising, financial services analytical applications infrastructure, financial services behavior detection platform, financial services trade-based anti money laundering, peoplesoft enterprise peopletools, fedora
Weakness
CWE-400, CWE-1333
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.