UbuntuUpdates.org

Package "ckeditor"

Name: ckeditor

Description:

text editor which can be embedded into web pages

Latest version: 4.22.1+dfsg1-2ubuntu0.24.10.1
Release: oracular (24.10)
Level: security
Repository: universe
Homepage: https://ckeditor.com

Links


Download "ckeditor"


Other versions of "ckeditor" in Oracular

Repository Area Version
base universe 4.22.1+dfsg1-2
updates universe 4.22.1+dfsg1-2ubuntu0.24.10.1

Changelog

Version: 4.22.1+dfsg1-2ubuntu0.24.10.1 2025-02-06 03:06:50 UTC

  ckeditor (4.22.1+dfsg1-2ubuntu0.24.10.1) oracular-security; urgency=medium

  * SECURITY UPDATE: Cross Site Scripting
    - debian/patches/CVE-2024-24815.patch: Fix CDATA parsing logic
    - debian/patches/CVE-2024-24816.patch: Updated samples
    - CVE-2024-24815
    - CVE-2024-24816
  * SECURITY UPDATE: Denial of service
    - debian/patches/CVE-2024-43411.patch: Use exception handling when
      parsing a JSON request
    - CVE-2024-43411

 -- Bruce Cable <email address hidden> Tue, 04 Feb 2025 11:57:11 +1100

CVE-2024-24815 CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered in the core HTML parsi
CVE-2024-24816 CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability vulnerability has been discovered in versi
CVE-2024-43411 CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A theoretical vulnerability has been identified in CKEditor 4.22 (and above). I



About   -   Send Feedback to @ubuntu_updates