Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-14863

Опубликовано: 02 янв. 2020
Источник: debian

Описание

There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
angular.jsfixed1.5.3-2package

Примечания

  • https://snyk.io/vuln/npm:angular:20150807

  • https://github.com/angular/angular.js/commit/f33ce173c90736e349cf594df717ae3ee41e0f7a

  • https://github.com/angular/angular.js/pull/12524

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 6 лет назад

There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.

CVSS3: 7.1
redhat
больше 6 лет назад

There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.

CVSS3: 6.1
nvd
около 6 лет назад

There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.

CVSS3: 6.1
github
почти 6 лет назад

AngularJS Cross-site Scripting due to failure to sanitize `xlink.href` attributes