Log

ASA-202106-27 edited at 11 Jun 2021 16:00:42
ASA-202106-26 edited at 11 Jun 2021 16:00:37
ASA-202106-25 edited at 11 Jun 2021 16:00:34
ASA-202106-24 edited at 11 Jun 2021 16:00:30
ASA-202106-23 edited at 11 Jun 2021 16:00:26
ASA-202106-22 edited at 11 Jun 2021 16:00:22
ASA-202106-21 edited at 11 Jun 2021 16:00:18
ASA-202106-20 edited at 11 Jun 2021 16:00:15
AVG-2069 edited at 11 Jun 2021 15:54:35
Severity
- Unknown
+ High
CVE-2021-33829 edited at 11 Jun 2021 15:54:35
Severity
- Unknown
+ High
Remote
- Unknown
+ Remote
Type
- Unknown
+ Cross-site scripting
Description
+ Drupal core uses the third-party CKEditor library. This library has an error in parsing HTML that could lead to a cross-site scripting (XSS) attack. CKEditor 4.16.1 and later, as bundled with Drupal 9.1.9, include the fix.
References
+ https://www.drupal.org/sa-core-2021-003
+ https://ckeditor.com/blog/ckeditor-4.16.1-with-accessibility-enhancements/#improvements-for-comments-in-html-parser
Notes
AVG-2069 created at 11 Jun 2021 15:52:16
Packages
+ drupal
Issues
+ CVE-2021-33829
Status
+ Vulnerable
Severity
+ Unknown
Affected
+ 9.1.7-1
Fixed
Ticket
Advisory qualified
+ Yes
References
Notes
CVE-2021-33829 created at 11 Jun 2021 15:52:16