CVE-2021-26272
26.01.2021, 21:15
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).Enginsight
Vendor | Product | Version |
---|---|---|
ckeditor | ckeditor | 4.0 ≤ 𝑥 < 4.16 |
oracle | agile_plm | 9.3.5 |
oracle | agile_plm | 9.3.6 |
oracle | application_express | 𝑥 < 21.1.0 |
oracle | banking_party_management | 2.7.0 |
oracle | commerce_merchandising | 11.3.0 ≤ 𝑥 ≤ 11.3.2 |
oracle | commerce_merchandising | 11.1.0 |
oracle | commerce_merchandising | 11.2.0 |
oracle | financial_services_analytical_applications_infrastructure | 8.0.6 ≤ 𝑥 ≤ 8.0.9 |
oracle | financial_services_analytical_applications_infrastructure | 8.1.0 |
oracle | financial_services_analytical_applications_infrastructure | 8.1.1 |
oracle | financial_services_model_management_and_governance | 8.0.8.0.0 ≤ 𝑥 ≤ 8.1.0.0.0 |
oracle | jd_edwards_enterpriseone_tools | 𝑥 < 9.2.6.0 |
oracle | siebel_ui_framework | 𝑥 ≤ 21.9 |
oracle | webcenter_sites | 12.2.1.3.0 |
oracle | webcenter_sites | 12.2.1.4.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References