The Drupal project uses the CKEditor library for WYSIWYG editing. CKEditor has released a security update that impacts Drupal, along with a hotfix for that update.
Vulnerabilities are possible if Drupal is configured to allow use of the CKEditor library for WYSIWYG editing. An attacker that can create or edit content (even without access to CKEditor themselves) may be able to exploit one or more Cross-Site Scripting (XSS) vulnerabilities to target users with access to the WYSIWYG CKEditor, including site admins with privileged access.
For more information, see CKEditor’s security advisories:
CVE-2021-41165: HTML comments vulnerability allowing to execute JavaScript code
CVE-2021-41164: Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTML
This advisory is not covered by Drupal Steward.
Install the latest version:
If you are using Drupal 9.2, update to Drupal 9.2.9.
If you are using Drupal 9.1, update to Drupal 9.1.14.
If you are using Drupal 8.9, update to Drupal 8.9.20.
Versions of Drupal prior to 9.1.x are end-of-life and do not receive security coverage.
Note that Drupal 8 has reached its end of life so this is the final security release provided for Drupal 8.
Drupal 7 core does not include the CKEditor module and therefore is not affected.
See the CKEditor announcements above for the original reporters of the vulnerabilities.
Wim Leers
Greg Knaddison of the Drupal Security Team
Lauri Eskola
Ted Bowman
More Stories
chromium-120.0.6099.71-1.el9
FEDORA-EPEL-2023-a0fcd69d86 Packages in this update: chromium-120.0.6099.71-1.el9 Update description: Update to 120.0.6099.71 Update to 120.0.6099.62, upstream release fixes follow security issues:...
chromium-120.0.6099.71-1.el7
FEDORA-EPEL-2023-3782f9a3bf Packages in this update: chromium-120.0.6099.71-1.el7 Update description: Update to 120.0.6099.71 Update to 120.0.6099.62, upstream release fixes follow security issues:...
chromium-120.0.6099.71-1.el8
FEDORA-EPEL-2023-d1b0df83e0 Packages in this update: chromium-120.0.6099.71-1.el8 Update description: Update to 120.0.6099.71 Update to 120.0.6099.62, upstream release fixes follow security issues:...
doctl-1.101.0-2.fc40
FEDORA-2023-72ab10f1de Packages in this update: doctl-1.101.0-2.fc40 Update description: Automatic update for doctl-1.101.0-2.fc40. Changelog * Sat Dec 9 2023 Mikel Olasagasti...
seamonkey-2.53.18-1.el7
FEDORA-EPEL-2023-fd36857b5e Packages in this update: seamonkey-2.53.18-1.el7 Update description: Update to 2.53.18 Read More
seamonkey-2.53.18-1.el8
FEDORA-EPEL-2023-76db503610 Packages in this update: seamonkey-2.53.18-1.el8 Update description: Update to 2.53.18 Read More