CVE-2024-43411

EUVD-2024-2518
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A theoretical vulnerability has been identified in CKEditor 4.22 (and above). In a highly unlikely scenario where an attacker gains control over the https://cke4.ckeditor.com domain, they could potentially execute an attack on CKEditor 4 instances. The issue impacts only editor instances with enabled version notifications. Please note that this feature is disabled by default in all CKEditor 4 LTS versions. Therefore, if you use CKEditor 4 LTS, it is highly unlikely that you are affected by this vulnerability. If you are unsure, please contact us. The fix is available in version 4.25.0-lts.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.1 LOW
NETWORK
HIGH
HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N
GitHub_MCNA
3.1 LOW
NETWORK
HIGH
HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 18%
Debian logo
Debian Releases
Debian Product
Codename
ckeditor
bookworm
4.19.1+dfsg-1
not-affected
bullseye
4.16.0+dfsg-2
not-affected
sid
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ckeditor3
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
oracular
ignored
plucky
needs-triage
questing
dne
ldap-account-manager
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
oracular
ignored
plucky
needs-triage
questing
needs-triage
xenial
needs-triage
request-tracker4
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
oracular
ignored
plucky
needs-triage
questing
needs-triage
xenial
needs-triage
ckeditor
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
Fixed 4.22.1+dfsg1-2ubuntu0.24.04.1~esm1
released
oracular
Fixed 4.22.1+dfsg1-2ubuntu0.24.10.1
released
plucky
Fixed 4.22.1+dfsg1-2ubuntu1
released
questing
Fixed 4.22.1+dfsg1-2ubuntu1
released
xenial
not-affected