CVE-2021-26271 PUBLISHED

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).

EPSS 0.62% · 69.8th percentile

Risk Scores

EPSS Score
0.62%
69.8th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSckeditor0, 4.5.7+dfsg-2ubuntu0.18.04.1+esm2, 4.5.7+dfsg-2ubuntu0.18.04.1+esm1
Ubuntu:Pro:20.04:LTSckeditor4.12.1+dfsg-1ubuntu0.1+esm2, 0, 4.11.1+dfsg-1
Ubuntu:Pro:16.04:LTSckeditor4.5.6+dfsg-1, 4.4.4+dfsg1-3, 0

Timeline

References

Open in Interactive Console →