5
CVSSv2

CVE-2022-24729

Published: 16/03/2022 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop resulting in a browser tab freeze. A patch is available in version 4.18.0. There are currently no known workarounds.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ckeditor ckeditor

drupal drupal

oracle peoplesoft enterprise peopletools 8.58

oracle peoplesoft enterprise peopletools 8.59

oracle commerce merchandising 11.3.2

oracle financial services trade-based anti money laundering 8.0.7

oracle financial services trade-based anti money laundering 8.0.8

fedoraproject fedora 36

oracle financial services analytical applications infrastructure 8.1.2.0

oracle financial services analytical applications infrastructure 8.1.1.0

oracle application express

oracle financial services analytical applications infrastructure 8.1.2.1

oracle financial services behavior detection platform

oracle financial services analytical applications infrastructure

oracle financial services behavior detection platform 8.0.8.0

oracle financial services behavior detection platform 8.0.7.0

fedoraproject fedora 37

Vendor Advisories

Debian Bug report logs - #1015217 ckeditor3: CVE-2014-5191 CVE-2018-17960 CVE-2021-26271 CVE-2021-33829 CVE-2021-37695 CVE-2021-41165 CVE-2022-24728 CVE-2022-24729 Package: src:ckeditor3; Maintainer for src:ckeditor3 is Horde Maintainers <team+debian-horde-team@trackerdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inut ...