CVE-2021-33829 - log back

CVE-2021-33829 edited at 11 Jun 2021 15:54:35
Severity
- Unknown
+ High
Remote
- Unknown
+ Remote
Type
- Unknown
+ Cross-site scripting
Description
+ Drupal core uses the third-party CKEditor library. This library has an error in parsing HTML that could lead to a cross-site scripting (XSS) attack. CKEditor 4.16.1 and later, as bundled with Drupal 9.1.9, include the fix.
References
+ https://www.drupal.org/sa-core-2021-003
+ https://ckeditor.com/blog/ckeditor-4.16.1-with-accessibility-enhancements/#improvements-for-comments-in-html-parser
Notes
CVE-2021-33829 created at 11 Jun 2021 15:52:16