漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Regular expression Denial of Service in multiple packages
Vulnerability Description
CKEditor 5 provides a WYSIWYG editing solution. This CVE affects the following npm packages: ckeditor5-engine, ckeditor5-font, ckeditor5-image, ckeditor5-list, ckeditor5-markdown-gfm, ckeditor5-media-embed, ckeditor5-paste-from-office, and ckeditor5-widget. Following an internal audit, a regular expression denial of service (ReDoS) vulnerability has been discovered in multiple CKEditor 5 packages. The vulnerability allowed to abuse particular regular expressions, which could cause a significant performance drop resulting in a browser tab freeze. It affects all users using the CKEditor 5 packages listed above at version <= 26.0.0. The problem has been recognized and patched. The fix will be available in version 27.0.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Vulnerability Title
CKEditor 资源管理错误漏洞
Vulnerability Description
CKEditor是一套开源的、基于网页的文字编辑器。 CKEditor 5 存在资源管理错误漏洞,该漏洞源于一个正则表达式拒绝服务(ReDoS)漏洞。该漏洞允许滥用特定的正则表达式,这可能会导致性能显着下降,从而导致浏览器选项卡冻结。
CVSS Information
N/A
Vulnerability Type
N/A