Your submission was sent successfully! Close

CVE-2022-24728

Published: 16 March 2022

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.

Notes

AuthorNote
sbeattie
embedded copies of ckeditor are in ldap-account-manager,
rt4, and rt5
Priority

Medium

CVSS 3 base score: 5.4

Status

Package Release Status
ckeditor
Launchpad, Ubuntu, Debian
bionic Needs triage

focal Needs triage

impish Ignored
(reached end-of-life)
jammy Needs triage

trusty Does not exist

upstream Needs triage

xenial Ignored
(out of standard support)
ckeditor3
Launchpad, Ubuntu, Debian
bionic Needs triage

focal Needs triage

impish Ignored
(reached end-of-life)
jammy Needs triage

trusty Does not exist

upstream Needs triage

xenial Ignored
(out of standard support)
ldap-account-manager
Launchpad, Ubuntu, Debian
bionic Needs triage

focal Needs triage

impish Ignored
(reached end-of-life)
jammy Needs triage

trusty Does not exist

upstream Needs triage

xenial Ignored
(out of standard support)
request-tracker4
Launchpad, Ubuntu, Debian
bionic Needs triage

focal Needs triage

impish Ignored
(reached end-of-life)
jammy Needs triage

trusty Does not exist

upstream Needs triage

xenial Ignored
(out of standard support)