Input validation error in CKEditor - CVE-2021-26272
Published: January 26, 2021 / Updated: January 27, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a regular expression denial of service (ReDoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can trick the victim to paste a specially crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin) and perform a regular expression denial of service (ReDoS) attack.
Affected software
IBM Sterling Partner Engagement Manager
Oracle Agile PLM Framework
Oracle Commerce Merchandising
Oracle WebCenter Sites
IBM Engineering Requirements Management DOORS Next
Oracle Application Express
How to mitigate CVE-2021-26272
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.5, 6.2.4.2
IBM Engineering Requirements Management DOORS Next - update to 7.0.2 ifix 32
Oracle Application Express - update to 21.1.0
External References
Related Security Bulletins
- Denial of service in CKEditor
- Input validation error in Oracle Commerce Merchandising
- Multiple vulnerabilities in Oracle Agile PLM Framework
- Input validation error in Oracle Application Express
- Multiple vulnerabilities in Oracle WebCenter Sites
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS Next
- Multiple vulnerabilities in IBM Sterling Partner Engagement Manager Essentials Edition