GHSA-3rh3-wfr4-76mj

Suggest an improvement
Source
https://github.com/advisories/GHSA-3rh3-wfr4-76mj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/04/GHSA-3rh3-wfr4-76mj/GHSA-3rh3-wfr4-76mj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3rh3-wfr4-76mj
Aliases
Related
Published
2021-04-06T17:28:41Z
Modified
2023-11-08T04:04:44.281094Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Regular expression Denial of Service in multiple packages
Details

Impact

A regular expression denial of service (ReDoS) vulnerability has been discovered in multiple CKEditor 5 packages. The vulnerability allowed to abuse particular regular expressions, which could cause a significant performance drop resulting in a browser tab freeze. It affects all users using the CKEditor 5 packages listed above at version <= 26.0.0.

Patches

The problem has been recognized and patched. The fix will be available in version 27.0.0.

For more information

Email us at security@cksource.com if you have any questions or comments about this advisory.

Acknowledgements

The CKEditor 5 team would like to thank Yeting Li for recognizing and reporting these vulnerabilities.

Database specific
{
    "nvd_published_at": "2021-04-29T01:15:00Z",
    "github_reviewed_at": "2021-03-31T18:37:46Z",
    "severity": "MODERATE",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-400"
    ]
}
References

Affected packages

npm / @ckeditor/ckeditor5-engine

Package

Name
@ckeditor/ckeditor5-engine
View open source insights on deps.dev
Purl
pkg:npm/%40ckeditor/ckeditor5-engine

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
27.0.0

Database specific

{
    "last_known_affected_version_range": "<= 26.0.0"
}

npm / @ckeditor/ckeditor5-font

Package

Name
@ckeditor/ckeditor5-font
View open source insights on deps.dev
Purl
pkg:npm/%40ckeditor/ckeditor5-font

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
27.0.0

Database specific

{
    "last_known_affected_version_range": "<= 26.0.0"
}

npm / @ckeditor/ckeditor5-image

Package

Name
@ckeditor/ckeditor5-image
View open source insights on deps.dev
Purl
pkg:npm/%40ckeditor/ckeditor5-image

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
27.0.0

Database specific

{
    "last_known_affected_version_range": "<= 26.0.0"
}

npm / @ckeditor/ckeditor5-list

Package

Name
@ckeditor/ckeditor5-list
View open source insights on deps.dev
Purl
pkg:npm/%40ckeditor/ckeditor5-list

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
27.0.0

Database specific

{
    "last_known_affected_version_range": "<= 26.0.0"
}

npm / @ckeditor/ckeditor5-markdown-gfm

Package

Name
@ckeditor/ckeditor5-markdown-gfm
View open source insights on deps.dev
Purl
pkg:npm/%40ckeditor/ckeditor5-markdown-gfm

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
27.0.0

Database specific

{
    "last_known_affected_version_range": "<= 26.0.0"
}

npm / @ckeditor/ckeditor5-media-embed

Package

Name
@ckeditor/ckeditor5-media-embed
View open source insights on deps.dev
Purl
pkg:npm/%40ckeditor/ckeditor5-media-embed

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
27.0.0

Database specific

{
    "last_known_affected_version_range": "<= 26.0.0"
}

npm / @ckeditor/ckeditor5-paste-from-office

Package

Name
@ckeditor/ckeditor5-paste-from-office
View open source insights on deps.dev
Purl
pkg:npm/%40ckeditor/ckeditor5-paste-from-office

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
27.0.0

Database specific

{
    "last_known_affected_version_range": "<= 26.0.0"
}

npm / @ckeditor/ckeditor5-widget

Package

Name
@ckeditor/ckeditor5-widget
View open source insights on deps.dev
Purl
pkg:npm/%40ckeditor/ckeditor5-widget

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
27.0.0

Database specific

{
    "last_known_affected_version_range": "<= 26.0.0"
}