010-68421378
sales@cogitosoft.com
Categories
AddFlow  AmCharts JavaScript Stock Chart AmCharts 4: Charts Aspose.Total for Java Altova SchemaAgent Altova DatabaseSpy Altova MobileTogether Altova UModel  Altova MapForce Altova MapForce Server Altova Authentic Aspose.Total for .NET Altova RaptorXML Server ComponentOne Ultimate Chart FX for SharePoint Chart FX CodeCharge Studio ComponentOne Enterprise combit Report Server Combit List & Label 22 Controls for Visual C++ MFC Chart Pro for Visual C ++ MFC DbVisualizer version 12.1 DemoCharge DXperience Subscription .NET DevExpress Universal Subscription Essential Studio for ASP.NET MVC FusionCharts Suite XT FusionCharts for Flex  FusionExport V2.0 GrapeCity TX Text Control .NET for WPF GrapeCity Spread Studio Highcharts Gantt Highcharts 10.0 版 HelpNDoc Infragistics Ultimate  ImageKit9 ActiveX ImageKit.NET JetBrains--Fleet JetBrains-DataSpell JetBrains--DataGrip jQuery EasyUI jChart FX Plus OPC DA .NET Server Toolkit  OSS ASN.1/C Oxygen XML Author  OSS 4G NAS/C, C++ Encoder Decoder Library OSS ASN.1 Tools for C with 4G S1/X2 OSS ASN.1/C# OSS ASN.1/JAVA OSS ASN.1/C++ OPC HDA .NET Server Toolkit OPC DA .Net Client Development Component PowerBuilder redgate NET Developer Bundle Report Control for Visual C++ MFC  Sencha Test SPC Control Chart Tools for .Net Stimulsoft Reports.PHP Stimulsoft Reports.JS Stimulsoft Reports.Java Stimulsoft Reports. Ultimate Stimulsoft Reports.Wpf Stimulsoft Reports.Silverlight SlickEdit Source Insight Software Verify .Net Coverage Validator Toolkit Pro for VisualC++MFC TeeChart .NET Telerik DevCraft Complete Altova XMLSpy Zend Server

CKEditor v43.1.1 Release Highlights: Security fix introduced

CKEditor v43.1.1 Release Highlights: Security fix introduced

We’re releasing CKEditor 5 v43.1.1 to address a Cross-Site Scripting (XSS) vulnerability (CVE-2024-45613) discovered in the clipboard package, during a recent internal audit.

What is the latest version of CKEditor?

The latest version of CKEditor is v43.1.1 and includes an important security fix. We highly recommend updating to the latest version to keep your application secure.

UPDATED Security Fix for Clipboard Package

During an internal audit, a Cross-Site Scripting (XSS) vulnerability was discovered in the CKEditor 5 clipboard package (CVE-2024-45613). This vulnerability could potentially allow unauthorized JavaScript execution under specific configurations triggered by user actions.

This vulnerability impacts only those installations with the following editor configuration:

  • The Block Toolbar plugin is enabled.
  • One of the following plugins is also enabled:

1. General HTML Support with a configuration that permits unsafe markup

2. HTML Embed

Additionally, in this release we have implemented further hardening measures in parts of our codebase to address theoretical issues, none of which are exploitable in real scenarios. Regardless, the fixes were made proactively, in order to increase the overall security.

 

Quick Navigation;

© Copyright 2000-2023  COGITO SOFTWARE CO.,LTD. All rights reserved