HIGH · 7.6

CVE-2021-32808

ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allow...

Vulnerability Description

ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version >= 4.13.0. The problem has been recognized and patched. The fix will be available in version 4.16.2.

CVSS Score

7.6

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
HIGH
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
CkeditorCkeditor>= 4.13.0, < 4.16.2
FedoraprojectFedora33
OracleApplication Express< 21.1.4
OracleBanking Party Management2.7.0
OracleCommerce Guided Search11.3.2
OracleCommerce Merchandising11.3.2
OracleDocumaker12.6.3
OracleFinancial Services Analytical Applications Infrastructure>= 8.0.7, <= 8.1.1
OracleFinancial Services Model Management And Governance8.0.8.0.0
OracleJd Edwards Enterpriseone Tools<= 9.2.6.0
OraclePeoplesoft Enterprise Peopletools8.57
OracleSiebel Ui Framework<= 21.9
OracleWebcenter Sites12.2.1.3.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-32808?

CVE-2021-32808 is a vulnerability with a CVSS score of 7.6 (HIGH). ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allow...

How severe is CVE-2021-32808?

CVE-2021-32808 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-32808?

Check the references section above for vendor advisories and patch information. Affected products include: Ckeditor Ckeditor, Fedoraproject Fedora, Oracle Application Express, Oracle Banking Party Management, Oracle Commerce Guided Search.