CVE-2022-24729
16.03.2022, 17:15
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop resulting in a browser tab freeze. A patch is available in version 4.18.0. There are currently no known workarounds.Enginsight
Vendor | Product | Version |
---|---|---|
ckeditor | ckeditor | 4.0 ≤ 𝑥 < 4.18.0 |
drupal | drupal | 8.0.0 ≤ 𝑥 < 9.2.15 |
drupal | drupal | 9.3.0 ≤ 𝑥 < 9.3.8 |
oracle | application_express | 𝑥 < 22.1.1 |
oracle | commerce_merchandising | 11.3.2 |
oracle | financial_services_analytical_applications_infrastructure | 8.0.7.0.0 ≤ 𝑥 ≤ 8.1.0.0.0 |
oracle | financial_services_analytical_applications_infrastructure | 8.1.1.0 |
oracle | financial_services_analytical_applications_infrastructure | 8.1.2.0 |
oracle | financial_services_analytical_applications_infrastructure | 8.1.2.1 |
oracle | financial_services_behavior_detection_platform | 8.1.1.0 ≤ 𝑥 ≤ 8.1.2.1 |
oracle | financial_services_behavior_detection_platform | 8.0.7.0 |
oracle | financial_services_behavior_detection_platform | 8.0.8.0 |
oracle | financial_services_trade-based_anti_money_laundering | 8.0.7 |
oracle | financial_services_trade-based_anti_money_laundering | 8.0.8 |
oracle | peoplesoft_enterprise_peopletools | 8.58 |
oracle | peoplesoft_enterprise_peopletools | 8.59 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ckeditor |
| ||||||||||||||||||||
ckeditor3 |
| ||||||||||||||||||||
ldap-account-manager |
| ||||||||||||||||||||
request-tracker4 |
|
Common Weakness Enumeration
- CWE-400 - Uncontrolled Resource ConsumptionThe software does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
- CWE-1333 - Inefficient Regular Expression ComplexityThe product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.
References