{"id":"CVE-2021-41165","details":"CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version \u003c 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.","aliases":["BIT-drupal-2021-41165","GHSA-7h26-63m7-qhf2"],"modified":"2026-07-08T06:29:57.864560628Z","published":"2021-11-17T20:15:10.273Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"fixed":"22.1"}],"source":"CPE_RANGE","vendor_product":"oracle:application_express","cpes":["cpe:2.3:a:oracle:application_express:*:*:*:*:*:*:*:*"]},{"vendor_product":"oracle:banking_apis","cpes":["cpe:2.3:a:oracle:banking_apis:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"18.1"},{"last_affected":"18.3"}],"source":"CPE_RANGE"},{"cpes":["cpe:2.3:a:oracle:banking_digital_experience:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"18.1"},{"last_affected":"18.3"}],"source":"CPE_RANGE","vendor_product":"oracle:banking_digital_experience"},{"cpes":["cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.6:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"9.3.6"},{"last_affected":"9.3.6"}],"source":"CPE_STRING","vendor_product":"oracle:agile_product_lifecycle_management"},{"cpes":["cpe:2.3:a:oracle:banking_apis:19.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_apis:19.2:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_apis:20.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_apis:21.1:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"19.1"},{"last_affected":"19.1"},{"introduced":"19.2"},{"last_affected":"19.2"},{"introduced":"20.1"},{"last_affected":"20.1"},{"introduced":"21.1"},{"last_affected":"21.1"}],"source":"CPE_STRING","vendor_product":"oracle:banking_apis"},{"extracted_events":[{"introduced":"19.1"},{"last_affected":"19.1"},{"introduced":"19.2"},{"last_affected":"19.2"},{"introduced":"20.1"},{"last_affected":"20.1"},{"introduced":"21.1"},{"last_affected":"21.1"}],"source":"CPE_STRING","vendor_product":"oracle:banking_digital_experience","cpes":["cpe:2.3:a:oracle:banking_digital_experience:19.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_digital_experience:19.2:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_digital_experience:20.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_digital_experience:21.1:*:*:*:*:*:*:*"]},{"vendor_product":"oracle:commerce_guided_search","cpes":["cpe:2.3:a:oracle:commerce_guided_search:11.3.2:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"11.3.2"},{"last_affected":"11.3.2"}],"source":"CPE_STRING"},{"vendor_product":"oracle:peoplesoft_enterprise_peopletools","cpes":["cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*","cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.58"},{"last_affected":"8.58"},{"introduced":"8.59"},{"last_affected":"8.59"}],"source":"CPE_STRING"},{"vendor_product":"oracle:webcenter_portal","cpes":["cpe:2.3:a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"12.2.1.3.0"},{"last_affected":"12.2.1.3.0"},{"introduced":"12.2.1.4.0"},{"last_affected":"12.2.1.4.0"}],"source":"CPE_STRING"}]},"references":[{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujul2022.html"},{"type":"ADVISORY","url":"https://github.com/ckeditor/ckeditor4/blob/major/CHANGES.md#ckeditor-417"},{"type":"ADVISORY","url":"https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-7h26-63m7-qhf2"},{"type":"ADVISORY","url":"https://www.drupal.org/sa-core-2021-011"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuapr2022.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpujan2022.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ckeditor/ckeditor4","events":[{"introduced":"0"},{"fixed":"cab78d432999c8bcd8213a2e0786026a5f9a44dc"}],"database_specific":{"cpe":"cpe:2.3:a:ckeditor:ckeditor:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"4.17.0"}],"source":"CPE_RANGE"}}],"versions":["4.16.0","4.15.0","4.14.0","4.13.0","4.12.0","4.10.0","4.8.0","4.7.0","4.6.0","4.5.0","4.5.0-beta","4.4.1","4.4.0","4.2.3","4.2.2","4.2.1","4.2.0","4.2","4.1.0","4.1","4.1rc","4.0.1","4.0.0","4.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-41165.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/ckeditor/ckeditor4-releases","events":[{"introduced":"0"},{"fixed":"5a0d3c84b4bc9eb7d1ecd8dfa9b660eb691553c2"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:ckeditor:ckeditor:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"4.17.0"}]}}],"versions":["standard/4.16.2","standard/4.16.1","standard/4.16.0","standard/4.15.1","standard/4.15.0","standard/4.14.1","standard/4.14.0","standard/4.13.1","standard/4.13.0","standard/4.12.1","standard/4.12.0","standard/4.11.4","standard/4.11.3","standard/4.11.2","standard/4.11.1","standard/4.11.0","standard/4.10.1","standard/4.10.0","standard/4.9.2","standard/4.9.1","standard/4.9.0","standard/4.8.0","standard/4.7.3","standard/4.7.2","standard/4.7.1","standard/4.7.0","standard/4.6.2","standard/4.6.1","standard/4.6.0","standard/4.5.11","standard/4.5.10","standard/4.5.9","standard/4.5.8","standard/4.5.7","standard/4.5.6","standard/4.5.5","standard/4.5.4","standard/4.5.3","standard/4.5.2","standard/4.5.1","standard/4.5.0","standard/4.4.8","standard/4.4.7","standard/4.4.6","standard/4.4.5","standard/4.4.4","standard/4.4.3","standard/4.4.2","standard/4.4.1","standard/4.4.0","standard/4.3.5","standard/4.3.4","standard/4.3.3","4.3.2/standard","4.3.1/standard","4.3.0/standard","4.2.3/standard","4.2.2/standard","4.2.1/standard","4.2/standard","4.1.3/standard","4.1.2/standard","4.1.1/standard","4.1/standard","4.1rc/standard","4.0.1/standard","4.0/standard"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-41165.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/drupal/drupal","events":[{"introduced":"a412ca41cfc0d954fe3cb2dd982dc6ca049b1c70"},{"fixed":"e187f925ed6aa9d9d4b3121904c077aa54ba108a"},{"introduced":"5c6f14f762c9aef87cd2731818386f202ee8463c"},{"fixed":"0398571aae84442c8fad6e9ce307aefb8c293b20"},{"introduced":"943ecef3c0bc9822338252a7df6419aeb9253c9d"},{"fixed":"ae75f828134e57bb1aed2ffb2635e6b28fc0e040"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"8.9.0"},{"fixed":"8.9.20"},{"introduced":"9.1.0"},{"fixed":"9.1.14"},{"introduced":"9.2.0"},{"fixed":"9.2.9"}]}}],"versions":["8.9.19","9.1.13","9.2.8","9.2.7","8.9.18","9.1.12","9.2.5","8.9.17","9.1.11","9.2.3","8.9.16","9.1.10","9.2.1","9.2.0","9.1.8","8.9.15","9.1.6","9.1.5","9.1.4","8.9.12","9.1.2","9.1.1","8.9.11","9.1.0","8.9.8","8.9.5","8.9.4","8.9.3","8.9.2","8.9.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-41165.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}