Problem Note 67872: SAS® Model Studio contains a version of CKEditor with known vulnerabilities
Severity: Medium
Description: SAS Model Studio in SAS® Viya® 3.5 contains a vulnerable version of the third-party JavaScript library CKEditor (4.11.2).
Potential Impact: Users might unknowingly execute malicious code.
Click the Hot Fix tab in this note for a link to instructions about accessing and applying the software update.
Operating System and Release Information
SAS System | SAS Viya | Linux for x64 | 3.5 | 2021.1.1 | Viya | Viya |
Microsoft® Windows® for x64 | 3.5 | 2021.1.1 | Viya | Viya |
*
For software releases that are not yet generally available, the Fixed
Release is the software release in which the problem is planned to be
fixed.
SAS® Model Studio contains CKEditor 4.11.2, which has known vulnerabilities.
Type: | Problem Note |
Priority: | medium |
Date Modified: | 2021-05-28 15:55:43 |
Date Created: | 2021-05-07 00:19:43 |