CVE-2024-38356
MEDIUM6.1EPSS 0.74%TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option
描述
### Impact A [cross-site scripting (XSS)](https://owasp.org/www-community/attacks/xss/) vulnerability was discovered in TinyMCE’s content extraction code. When using the `noneditable_regexp` option, specially crafted HTML attributes containing malicious code were able to be executed when content was extracted from the editor. ### Patches This vulnerability has been patched in TinyMCE 7.2.0, TinyMCE 6.8.4 and TinyMCE 5.11.0 LTS by ensuring that, when using the `noneditable_regexp` option, any content within an attribute is properly verified to match the configured regular expression before being added. ### Fix To avoid this vulnerability: * Upgrade to TinyMCE 7.2.0 or higher. * Upgrade to TinyMCE 6.8.4 or higher for TinyMCE 6.x. * Upgrade to TinyMCE 5.11.0 LTS or higher for TinyMCE 5.x (only available as part of commercial [long-term support](https://www.tiny.cloud/long-term-support/) contract). ### References * [TinyMCE 6.8.4](https://www.tiny.cloud/docs/tinymce/6/6.8.4-release-notes/#overview) * [TinyMCE 7.2.0](https://www.tiny.cloud/docs/tinymce/7/7.2-release-notes/#overview) ### For more information If you have any questions or comments about this advisory: * Email us at [[email protected]](mailto:[email protected]) * Open an issue in the [TinyMCE repo](https://github.com/tinymce/tinymce/issues?q=is%3Aissue+is%3Aopen+sort%3Aupdated-desc)
受影響套件(4)
- npm/tinymcefrom 0, < 5.11.0
- NuGet/TinyMCEfrom 0, < 5.11.0
- Packagist/tinymce/tinymcefrom 0, < 5.11.0
- PyPI/django-tinymcefrom 0, < 4.1.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:N/SI:L/SA:L |
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
參考連結(9)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2024-38356
- PATCHhttps://github.com/tinymce/tinymce
- WEBhttps://github.com/tinymce/tinymce/commit/5acb741665a98e83d62b91713c800abbff43b00d
- WEBhttps://github.com/tinymce/tinymce/commit/a9fb858509f86dacfa8b01cfd34653b408983ac0
- WEBhttps://github.com/tinymce/tinymce/security/advisories/GHSA-9hcv-j9pv-qmph
- WEBhttps://owasp.org/www-community/attacks/xss
- WEBhttps://www.tiny.cloud/docs/tinymce/6/6.8.4-release-notes/#overview
- WEBhttps://www.tiny.cloud/docs/tinymce/7/7.2-release-notes/#overview
- WEBhttps://www.tiny.cloud/docs/tinymce/latest/7.2-release-notes/#overview