I was not able to find any documentation which lists libraries and versions. See my earlier response on the forum here.
I believe the current version is CKEditor 4.7.1
Currently CKEditor 4.7.1 is published to the Internet of which some security issues are known
Most vulnerabilities(CVE-2022-24728, CVE-2021-41165, CVE-2021-41164, CVE-2021-37695, CVE-2021-3280, CVE-2021-26272, CVE-2021-262, CVE-2020-9281) are being targeted for 8.7.5 patch release and higher versions.
The reason we haven’t updated CKEditor to a later version is because there are backwards compatibility issues, so we can’t just take any version and have our clients face breakages in the software. Therefore the vulnerabilities are mitigated in the wrapper around the library.
Hi @aggad: Thanks for sharing this. I could get it from console.
But, I couldn’t able to find the js file mentioned (both from rules explorer and from search). Is it because it is pz file? How are you able to search for it?
You can update the preferences from operator profile pic (Left bottom in DEV studio) > Preferences > Enable diagnostic features.
Save and relogin.
You should be able to search ‘pz’ rules after this.