tinymce 4.x has a vulnerability, could mosaico be distributed with 5.x by default? #685
Answered
by
bago
BarbieroDB1
asked this question in
Q&A
Replies: 1 comment
-
|
Beta Was this translation helpful? Give feedback.
0 replies
Answer selected by
BarbieroDB1
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
CVE-2022-23494 seems to affect tinyMCE versions <5, and mosaico currently uses tinyMCE v4.9.11 as default. #644 added support for newer tinyMCE versions and, indeed, I could just
npm install tinymce@5
and then usegrunt build
(with a few gruntfile changes) to create a mosaico distribution that uses tinyMCE 5.10.7 instead of the vulnerable 4.9.However, package.json.NOTES state
Are there any plans of updating mosaico to ship with tinyMCE 5 by default? Or maybe a separate branch? Is current mosaico even vulnerable to CVE-2022-23494 due to the underlying tinyMCE?
What's the status on this?
Beta Was this translation helpful? Give feedback.
All reactions