{"id":"USN-7258-1","summary":"ckeditor vulnerabilities","details":"Kevin Backhouse discovered that CKEditor did not properly sanitize HTML\ncontent. An attacker could possibly use this issue to perform cross site\nscripting and obtain sensitive information. This issue only affected\nUbuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.\n(CVE-2022-24728)\n\nIt was discovered that CKEditor did not properly handle the creation of\neditor instances in the Iframe Dialog and Media Embed packages. An\nattacker could possibly use this issue to perform cross site scripting\nand obtain sensitive information. This issue only affected\nUbuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.\n(CVE-2023-28439)\n\nIt was discovered that CKEditor did not properly handle parsing HTML\ncontent. An attacker could possibly use this issue to perform cross site\nscripting and obtain sensitive information.\n(CVE-2024-24815, CVE-2024-24816)\n\nIt was discovered that CKEditor did not properly sanitize version\nnotifications. An attacker could possibly use this issue to perform cross\nsite scripting and obtain sensitive information. This issue only affected\nUbuntu 24.04 LTS and Ubuntu 24.10. (CVE-2024-43411)\n","modified":"2026-02-10T04:46:30Z","published":"2025-02-06T01:26:17Z","upstream":["CVE-2022-24728","CVE-2023-28439","CVE-2024-24815","CVE-2024-24816","CVE-2024-43411","UBUNTU-CVE-2022-24728","UBUNTU-CVE-2023-28439","UBUNTU-CVE-2024-24815","UBUNTU-CVE-2024-24816","UBUNTU-CVE-2024-43411"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-7258-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-24728"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-28439"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-24815"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-24816"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-43411"}],"affected":[{"package":{"name":"ckeditor","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/ckeditor@4.5.7+dfsg-2ubuntu0.16.04.1~esm2?arch=source&distro=esm-apps/xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.5.7+dfsg-2ubuntu0.16.04.1~esm2"}]}],"versions":["4.4.4+dfsg1-3","4.5.6+dfsg-1","4.5.7+dfsg-1","4.5.7+dfsg-2","4.5.7+dfsg-2ubuntu0.16.04.1~esm1"],"ecosystem_specific":{"binaries":[{"binary_version":"4.5.7+dfsg-2ubuntu0.16.04.1~esm2","binary_name":"ckeditor"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7258-1.json","cves_map":{"ecosystem":"Ubuntu:Pro:16.04:LTS","cves":[]}}},{"package":{"name":"ckeditor","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/ckeditor@4.5.7+dfsg-2ubuntu0.18.04.1+esm1?arch=source&distro=esm-apps/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.5.7+dfsg-2ubuntu0.18.04.1+esm1"}]}],"versions":["4.5.7+dfsg-2","4.5.7+dfsg-2ubuntu0.18.04.1"],"ecosystem_specific":{"binaries":[{"binary_version":"4.5.7+dfsg-2ubuntu0.18.04.1+esm1","binary_name":"ckeditor"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7258-1.json","cves_map":{"ecosystem":"Ubuntu:Pro:18.04:LTS","cves":[]}}},{"package":{"name":"ckeditor","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/ckeditor@4.12.1+dfsg-1ubuntu0.1+esm1?arch=source&distro=esm-apps/focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.1+dfsg-1ubuntu0.1+esm1"}]}],"versions":["4.11.1+dfsg-1","4.12.1+dfsg-1","4.12.1+dfsg-1ubuntu0.1"],"ecosystem_specific":{"binaries":[{"binary_version":"4.12.1+dfsg-1ubuntu0.1+esm1","binary_name":"ckeditor"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7258-1.json","cves_map":{"ecosystem":"Ubuntu:Pro:20.04:LTS","cves":[]}}},{"package":{"name":"ckeditor","ecosystem":"Ubuntu:Pro:22.04:LTS","purl":"pkg:deb/ubuntu/ckeditor@4.16.2+dfsg-1ubuntu0.1~esm1?arch=source&distro=esm-apps/jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.16.2+dfsg-1ubuntu0.1~esm1"}]}],"versions":["4.16.0+dfsg-2","4.16.2+dfsg-1"],"ecosystem_specific":{"binaries":[{"binary_version":"4.16.2+dfsg-1ubuntu0.1~esm1","binary_name":"ckeditor"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7258-1.json","cves_map":{"ecosystem":"Ubuntu:Pro:22.04:LTS","cves":[]}}},{"package":{"name":"ckeditor","ecosystem":"Ubuntu:Pro:24.04:LTS","purl":"pkg:deb/ubuntu/ckeditor@4.22.1+dfsg1-2ubuntu0.24.04.1~esm1?arch=source&distro=esm-apps/noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.22.1+dfsg1-2ubuntu0.24.04.1~esm1"}]}],"versions":["4.22.1+dfsg1-2"],"ecosystem_specific":{"binaries":[{"binary_version":"4.22.1+dfsg1-2ubuntu0.24.04.1~esm1","binary_name":"ckeditor"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7258-1.json","cves_map":{"ecosystem":"Ubuntu:Pro:24.04:LTS","cves":[]}}}],"schema_version":"1.7.3"}