forked from rubysec/ruby-advisory-db
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathCVE-2020-9281.yml
More file actions
27 lines (27 loc) · 1.32 KB
/
CVE-2020-9281.yml
File metadata and controls
27 lines (27 loc) · 1.32 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
---
gem: ckeditor
cve: 2020-9281
ghsa: vcjf-mgcg-jxjq
url: https://github.com/ckeditor/ckeditor4
title: CKEditor 4.0 vulnerability in the HTML Data Processor
date: 2021-05-07
description: |
A cross-site scripting (XSS) vulnerability in the HTML Data Processor
for CKEditor 4.0 before 4.14.0 allows remote attackers to inject arbitrary web script
through a crafted "protected" comment (with the cke_protected syntax).
cvss_v3: 6.1
patched_versions:
- ">= 5.1.2"
related:
url:
- https://nvd.nist.gov/vuln/detail/CVE-2020-9281
- https://github.com/ckeditor/ckeditor4
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7OJ4BSS3VEAEXPNSOOUAXX6RDNECGZNO/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L322YA73LCV3TO7ORY45WQDAFJVNKXBE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M4HHYQ6N452XTCIROFMJOTYEUWSB6FR4/
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://github.com/advisories/GHSA-vcjf-mgcg-jxjq