A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*",
"cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*",
"cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "30"
},
{
"last_affected": "31"
},
{
"last_affected": "32"
}
],
"source": "CPE_FIELD",
"vendor_product": "fedoraproject:fedora"
},
{
"cpes": [
"cpe:2.3:a:oracle:agile_plm:9.3.5:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "9.3.5"
},
{
"last_affected": "9.3.6"
}
],
"source": "CPE_FIELD",
"vendor_product": "oracle:agile_plm"
},
{
"cpes": [
"cpe:2.3:a:oracle:application_express:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"fixed": "20.2"
}
],
"source": "CPE_FIELD",
"vendor_product": "oracle:application_express"
},
{
"cpes": [
"cpe:2.3:a:oracle:banking_enterprise_default_management:2.10.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_enterprise_default_management:2.12.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_enterprise_default_management:2.6.2:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_enterprise_default_management:2.7.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_enterprise_default_management:2.7.1:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "2.6.2"
},
{
"last_affected": "2.7.0"
},
{
"last_affected": "2.7.1"
},
{
"last_affected": "2.10.0"
},
{
"last_affected": "2.12.0"
}
],
"source": "CPE_FIELD",
"vendor_product": "oracle:banking_enterprise_default_management"
},
{
"cpes": [
"cpe:2.3:a:oracle:banking_enterprise_default_managment:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "2.3.0"
},
{
"last_affected": "2.4.0"
}
],
"source": "CPE_FIELD",
"vendor_product": "oracle:banking_enterprise_default_managment"
},
{
"cpes": [
"cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"fixed": "9.2.5.2"
}
],
"source": "CPE_FIELD",
"vendor_product": "oracle:jd_edwards_enterpriseone_tools"
},
{
"cpes": [
"cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "8.56"
},
{
"last_affected": "8.57"
},
{
"last_affected": "8.58"
}
],
"source": "CPE_FIELD",
"vendor_product": "oracle:peoplesoft_enterprise_peopletools"
},
{
"cpes": [
"cpe:2.3:a:oracle:siebel_apps_-_customer_order_management:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"fixed": "21.0"
}
],
"source": "CPE_FIELD",
"vendor_product": "oracle:siebel_apps_-_customer_order_management"
},
{
"cpes": [
"cpe:2.3:a:oracle:webcenter_portal:11.1.1.9.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "11.1.1.9.0"
},
{
"last_affected": "12.2.1.3.0"
},
{
"last_affected": "12.2.1.4.0"
}
],
"source": "CPE_FIELD",
"vendor_product": "oracle:webcenter_portal"
}
]
}