{"id":"GHSA-42wq-rch8-6f6j","summary":"CKEditor5 cross-site scripting vulnerability caused by the editor instance destroying process","details":"### Affected packages\n@ckeditor/ckeditor5-markdown-gfm\n@ckeditor/ckeditor5-html-support\n@ckeditor/ckeditor5-html-embed\n\n### Impact\nA cross-site scripting vulnerability has been discovered affecting three optional CKEditor 5's packages. The vulnerability allowed to trigger a JavaScript code after fulfilling special conditions:\n\na) Using one of the affected packages. In case of `ckeditor5-html-support` and `ckeditor5-html-embed`, additionally, it was required to use a configuration that allows unsafe markup inside the editor,\nb) Initializing the editor on an element and using an element other than `\u003ctextarea\u003e` as a base,\nc) Destroying the editor instance.\n\nThe root cause of the issue was a mechanism responsible for updating the source element with the markup coming from the CKEditor 5 data pipeline after destroying the editor. \n\nThis vulnerability might affect a small percent of integrators that depend on dynamic editor initialization/destroy and use [Markdown](https://ckeditor.com/docs/ckeditor5/latest/features/markdown.html), [General HTML Support](https://ckeditor.com/docs/ckeditor5/latest/features/general-html-support.html) or [HTML embed](https://ckeditor.com/docs/ckeditor5/latest/features/html-embed.html) features.\n\n### Patches\nThe problem has been recognized and patched. The fix will be available in version 35.0.1.\n\n### For more information\nEmail us at [security@cksource.com](mailto:security@cksource.com) if you have any questions or comments about this advisory.\n","aliases":["CVE-2022-31175"],"modified":"2023-11-08T04:09:28.770716Z","published":"2022-08-06T09:40:43Z","database_specific":{"nvd_published_at":"2022-08-03T19:15:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-08-06T09:40:43Z"},"references":[{"type":"WEB","url":"https://github.com/ckeditor/ckeditor5/security/advisories/GHSA-42wq-rch8-6f6j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-31175"},{"type":"WEB","url":"https://ckeditor.com/docs/ckeditor5/latest/features/general-html-support.html"},{"type":"WEB","url":"https://ckeditor.com/docs/ckeditor5/latest/features/html-embed.html"},{"type":"WEB","url":"https://ckeditor.com/docs/ckeditor5/latest/features/markdown.html"},{"type":"PACKAGE","url":"https://github.com/ckeditor/ckeditor5"}],"affected":[{"package":{"name":"@ckeditor/ckeditor5-markdown-gfm","ecosystem":"npm","purl":"pkg:npm/%40ckeditor/ckeditor5-markdown-gfm"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"35.0.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/08/GHSA-42wq-rch8-6f6j/GHSA-42wq-rch8-6f6j.json"}},{"package":{"name":"@ckeditor/ckeditor5-html-support","ecosystem":"npm","purl":"pkg:npm/%40ckeditor/ckeditor5-html-support"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"35.0.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/08/GHSA-42wq-rch8-6f6j/GHSA-42wq-rch8-6f6j.json"}},{"package":{"name":"@ckeditor/ckeditor5-html-embed","ecosystem":"npm","purl":"pkg:npm/%40ckeditor/ckeditor5-html-embed"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"35.0.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/08/GHSA-42wq-rch8-6f6j/GHSA-42wq-rch8-6f6j.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L"}]}