Bug 2263228 (CVE-2024-24815) - CVE-2024-24815 ckeditor: cross-site scripting vulnerability via incorrect CDATA detection
Summary: CVE-2024-24815 ckeditor: cross-site scripting vulnerability via incorrect CDA...
Keywords:
Status: NEW
Alias: CVE-2024-24815
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2263230 2263229
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-02-07 17:40 UTC by Robb Gatica
Modified: 2024-02-07 17:40 UTC (History)
0 users

Fixed In Version: ckeditor4 4.24.0-lts
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Robb Gatica 2024-02-07 17:40:16 UTC
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered in the core HTML parsing module in versions of CKEditor4 prior to 4.24.0-lts. It may affect all editor instances that enabled full-page editing mode or enabled CDATA elements in Advanced Content Filtering configuration (defaults to `script` and `style` elements). The vulnerability allows attackers to inject malformed HTML content bypassing Advanced Content Filtering mechanism, which could result in executing JavaScript code. An attacker could abuse faulty CDATA content detection and use it to prepare an intentional attack on the editor. A fix is available in version 4.24.0-lts.

https://ckeditor.com/docs/ckeditor4/latest/api/CKEDITOR_dtd.html#property-S-cdata
https://ckeditor.com/docs/ckeditor4/latest/features/fullpage.html)
https://ckeditor.com/docs/ckeditor4/latest/guide/dev_advanced_content_filter.html
https://github.com/ckeditor/ckeditor4/commit/8ed1a3c93d0ae5f49f4ecff5738ab8a2972194cb
https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-fq6h-4g8v-qqvm

Comment 1 Robb Gatica 2024-02-07 17:40:32 UTC
Created ckeditor tracking bugs for this issue:

Affects: epel-all [bug 2263230]
Affects: fedora-all [bug 2263229]


Note You need to log in before you can comment on or make changes to this bug.