---
title: "CVE-2022-24729"
canonical: "https://kb.cynergy.app/space/MD/923664453/CVE-2022-24729"
format: markdown
---
**Description**

Certain versions of [Ckeditor](https://cve.report/software/ckeditor/ckeditor) from [Ckeditor](https://cve.report/vendor/ckeditor) contain the following vulnerability:

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. This problem has been patched in version 4.18.0. There are currently no known workarounds.

**Published On**

03/16/2022

**Updated On**

10/24/2022

**Trending**

FALSE

**CWE**

<u>[CWE-20](http://cwe.mitre.org/data/definitions/20.html)</u>

**Exploit**


**Mitigation:**

![image](media://8228968e-37b2-43ae-ac8a-c02e3649dc78)

Cynergy has an automated mitigation capability that requires integration with your WAF provider.

Once integrated, you can request “Protect with WAF”

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately</span>

 

**Remediation**

- [283229](https://cve.report/qid/283229) Fedora Security Update for ckeditor (FEDORA-2022-b61dfd219b)
- [730408](https://cve.report/qid/730408) Drupal Core CKEDITOR library Cross-Site Scripting (XSS) Vulnerability (SA-CORE-2022-005)


**Reference**

|  |  |  |
| --- | --- | --- |
| HTML processing vulnerability allowing to execute JavaScript code · Advisory · ckeditor/ckeditor4 · GitHub | [http://github.com](http://github.com)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| Code refactoring. · ckeditor/ckeditor4@d158413 · GitHub | [http://github.com](http://github.com)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| CKEditor 4.18.0 | [CKEditor.com](http://CKEditor.com) | [http://ckeditor.com](http://ckeditor.com)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| [SECURITY] Fedora 36 Update: ckeditor-4.20.0-1.fc36 - package-announce - Fedora Mailing-Lists | [http://lists.fedoraproject.org](http://lists.fedoraproject.org)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| Access to this page has been denied. | [http://www.drupal.org](http://www.drupal.org)   
<span style="color: #ffffff">**text/html**</span>  
<span style="color: #ffffff">**Inactive LinkNot Archived**</span> | ![URL Logo]() |
| Oracle Critical Patch Update Advisory - July 2022 | [http://www.oracle.com](http://www.oracle.com)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |