Bug 1139487 (CVE-2014-5191) - CVE-2014-5191 ckeditor: cross-site scripting flaw in the preview plug-in
Summary: CVE-2014-5191 ckeditor: cross-site scripting flaw in the preview plug-in
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: CVE-2014-5191
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1139488 1139489
Blocks:
TreeView+ depends on / blocked
 
Reported: 2014-09-09 05:04 UTC by Murray McAllister
Modified: 2019-09-29 13:21 UTC (History)
4 users (show)

Fixed In Version: ckeditor 4.4.3
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-02-24 07:29:10 UTC


Attachments (Terms of Use)

Description Murray McAllister 2014-09-09 05:04:33 UTC
The 4.4.3 release of ckeditor fixes a cross-site scripting (XSS) flaw in ckeditor:

http://ckeditor.com/release/CKEditor-4.4.3

This may be the fix:

https://github.com/ckeditor/ckeditor-dev/commit/fd4f17ce11eb398e844c9056c0e25087492a122b

The ckeditor and drupal7-ckeditor packages in Fedora and EPEL do not have this plug-in. The python-django-ckeditor packages look like they may be affected.

Comment 1 Murray McAllister 2014-09-09 05:06:19 UTC
Created python-django-ckeditor tracking bugs for this issue:

Affects: fedora-all [bug 1139488]
Affects: epel-6 [bug 1139489]

Comment 3 Shawn Iwinski 2019-02-24 07:29:10 UTC
Tried to request if this tracking bug can be closed since all dependent bugs have been closed, but received the following Bugzilla error:

>  You can't ask Murray McAllister <mmcallis@redhat.com> because that account is disabled.

So, closing this bug.


Note You need to log in before you can comment on or make changes to this bug.