CVE-2022-24729
moderate-risk
Published 2022-03-16
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop resulting in a browser tab freeze. A patch is available in version 4.18.0. There are currently no known workarounds.
Do I need to act?
-
0.86% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
6
CVSS 6.5/10
Medium
NETWORK
/ LOW complexity
Affected Products (17)
Commerce Merchandising
Financial Services Trade-Based Anti Money Laundering
Financial Services Trade-Based Anti Money Laundering
Affected Vendors
References (12)
Release Notes
https://ckeditor.com/cke4/release/CKEditor-4.18.0
Third Party Advisory
https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-f6rf-9m92-x2hh
Release Notes
https://ckeditor.com/cke4/release/CKEditor-4.18.0
Third Party Advisory
https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-f6rf-9m92-x2hh
46
/ 100
moderate-risk
Severity
24/34 · High
Exploitability
3/34 · Minimal
Exposure
19/34 · Moderate