← Retour
CVE-2021-41164
high
CVSS 8.2
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The...
Résumé
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result i...
Résumé IA openai / gpt-4o
Une vulnérabilité référencée **CVE-2021-41164** a été découverte dans ckeditor.
Des informations confidentielles peuvent être exposées. Score CVSS : 8.2/10.
Action : appliquez le correctif officiel de l'éditeur.
En cas de doute, contactez votre service informatique ou cherchez « ckeditor CVE-2021-41164 » sur le site de l'éditeur.
CVE-2021-41164 (ckeditor) — CWE-79 / CVSS v3 8.2
Vecteur d'attaque : distant (réseau)
Versions affectées : `< 4.17.0`
Plan : 1) Audit SBOM, 2) Mise à jour staging→prod, 3) Surveillance WAF/proxy sur les endpoints affectés, 4) Recherche d'IOC dans les logs.
Réfs : voir GHSA / avis éditeur / version corrigée liés sur cette page.
❓ Quel est le problème
CKEditor4のACFモジュールにおける不正なHTML注入の脆弱性。
📍 Périmètre concerné
CKEditor4のバージョン4.17.0未満のすべてのユーザー。
🔥 Gravité
この脆弱性により、不正なHTMLを通じてJavaScriptコードが実行される可能性があるため、非常に重要です。
🔧 Comment corriger
バージョン4.17.0にアップデートしてください。
🛡️ Contournement
情報なし
🔍 Détection
CKEditor4のバージョン番号を確認して、4.17.0未満である場合は影響を受けている可能性があります。
Références
- advisory af854a3a-2127-422b-91ae-364da2661108
- advisory af854a3a-2127-422b-91ae-364da2661108
- patch af854a3a-2127-422b-91ae-364da2661108
- patch af854a3a-2127-422b-91ae-364da2661108
- patch af854a3a-2127-422b-91ae-364da2661108
- web af854a3a-2127-422b-91ae-364da2661108
- web af854a3a-2127-422b-91ae-364da2661108
- web af854a3a-2127-422b-91ae-364da2661108