2024-12-08 03:06:42 +00:00

64 lines
3.0 KiB
JSON

{
"id": "CVE-2024-43411",
"sourceIdentifier": "security-advisories@github.com",
"published": "2024-08-21T16:15:08.570",
"lastModified": "2024-08-21T17:25:08.560",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A theoretical vulnerability has been identified in CKEditor 4.22 (and above). In a highly unlikely scenario where an attacker gains control over the https://cke4.ckeditor.com domain, they could potentially execute an attack on CKEditor 4 instances. The issue impacts only editor instances with enabled version notifications. Please note that this feature is disabled by default in all CKEditor 4 LTS versions. Therefore, if you use CKEditor 4 LTS, it is highly unlikely that you are affected by this vulnerability. If you are unsure, please contact us. The fix is available in version 4.25.0-lts."
},
{
"lang": "es",
"value": "CKEditor4 es un editor HTML de c\u00f3digo abierto de lo que ves es lo que obtienes. Se ha identificado una vulnerabilidad te\u00f3rica en CKEditor 4.22 (y superiores). En un escenario muy poco probable en el que un atacante obtenga control sobre el dominio https://cke4.ckeditor.com, podr\u00eda ejecutar un ataque en instancias de CKEditor 4. El problema afecta solo a las instancias del editor con notificaciones de versi\u00f3n habilitadas. Tenga en cuenta que esta funci\u00f3n est\u00e1 deshabilitada de forma predeterminada en todas las versiones de CKEditor 4 LTS. Por lo tanto, si utiliza CKEditor 4 LTS, es muy poco probable que se vea afectado por esta vulnerabilidad. Si no est\u00e1 seguro, por favor cont\u00e1ctenos. La soluci\u00f3n est\u00e1 disponible en la versi\u00f3n 4.25.0-lts."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "security-advisories@github.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N",
"baseScore": 3.1,
"baseSeverity": "LOW",
"attackVector": "NETWORK",
"attackComplexity": "HIGH",
"privilegesRequired": "HIGH",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 0.5,
"impactScore": 2.5
}
]
},
"weaknesses": [
{
"source": "security-advisories@github.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"references": [
{
"url": "https://github.com/ckeditor/ckeditor4/commit/b5069c9cb769ea22eae1cbd7200f22b1cf2e3a7f",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-6v96-m24v-f58j",
"source": "security-advisories@github.com"
}
]
}