It was possible to execute a ReDoS-type attack inside CKEditor 4 prior to 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ckeditor ckeditor |
||
oracle agile plm 9.3.5 |
||
oracle agile plm 9.3.6 |
||
oracle application express |
||
oracle banking party management 2.7.0 |
||
oracle commerce merchandising |
||
oracle commerce merchandising 11.1.0 |
||
oracle commerce merchandising 11.2.0 |
||
oracle financial services analytical applications infrastructure |
||
oracle financial services analytical applications infrastructure 8.1.0 |
||
oracle financial services analytical applications infrastructure 8.1.1 |
||
oracle financial services model management and governance |
||
oracle jd edwards enterpriseone tools |
||
oracle siebel ui framework |
||
oracle webcenter sites 12.2.1.3.0 |
||
oracle webcenter sites 12.2.1.4.0 |