Input validation error in CKEditor - CVE-2021-26272

 

Input validation error in CKEditor - CVE-2021-26272

Published: January 26, 2021 / Updated: January 27, 2021


Vulnerability identifier: #VU50054
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-26272
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a regular expression denial of service (ReDoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can trick the victim to paste a specially crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin) and perform a regular expression denial of service (ReDoS) attack.


Affected software

CKEditor
IBM Sterling Partner Engagement Manager
Oracle Agile PLM Framework
Oracle Commerce Merchandising
Oracle WebCenter Sites
IBM Engineering Requirements Management DOORS Next
Oracle Application Express

How to mitigate CVE-2021-26272

Install updates from vendor's website.

CKEditor - update to 4.16.0
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.5, 6.2.4.2
IBM Engineering Requirements Management DOORS Next - update to 7.0.2 ifix 32
Oracle Application Express - update to 21.1.0

External References

Related Security Bulletins