ckeditor / ckeditor4

The best enterprise-grade WYSIWYG editor. Fully customizable with countless features and plugins.
https://ckeditor.com/ckeditor-4
Other
5.79k stars 2.48k forks source link

backport the security patch of CVE-2024-43411 #5524

Closed Crispy-fried-chicken closed 1 month ago

Crispy-fried-chicken commented 1 month ago

Here is a vulnerability which is fixed in the master branch (https://github.com/ckeditor/ckeditor4/commit/b5069c9cb769ea22eae1cbd7200f22b1cf2e3a7f) but is not fixed in the branch of 4.24.x, maybe it should be backported?

jacekbogdanski commented 1 month ago

@Crispy-fried-chicken we don't provide backpatching, you should update to 4.25.0-LTS that includes the patch.