Vulnerability Description
A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ckeditor | Ckeditor | >= 4.14.0, < 4.16.1 |
| Fedoraproject | Fedora | 33 |
| Drupal | Drupal | >= 8.9.0, < 8.9.16 |
| Debian | Debian Linux | 9.0 |
Related Weaknesses (CWE)
References
- https://ckeditor.com/blog/ckeditor-4.16.1-with-accessibility-enhancements/#improPatchRelease NotesVendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/11/msg00007.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://www.drupal.org/sa-core-2021-003PatchThird Party Advisory
- https://ckeditor.com/blog/ckeditor-4.16.1-with-accessibility-enhancements/#improPatchRelease NotesVendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/11/msg00007.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://www.drupal.org/sa-core-2021-003PatchThird Party Advisory
FAQ
What is CVE-2021-33829?
CVE-2021-33829 is a vulnerability with a CVSS score of 6.1 (MEDIUM). A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted c...
How severe is CVE-2021-33829?
CVE-2021-33829 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-33829?
Check the references section above for vendor advisories and patch information. Affected products include: Ckeditor Ckeditor, Fedoraproject Fedora, Drupal Drupal, Debian Debian Linux.