Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r5fx-8r73-v86c

Опубликовано: 14 фев. 2020
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

AngularJS Cross-site Scripting due to failure to sanitize xlink.href attributes

Versions of angular prior to 1.5.0-beta.1 are vulnerable to Cross-Site Scripting. The package fails to sanitize xlink:href attributes, which may allow attackers to execute arbitrary JavaScript in a victim's browser if the value is user-controlled.

Recommendation

Upgrade to version 1.5.0-beta.1 or later.

Пакеты

Наименование

angular

npm
Затронутые версииВерсия исправления

< 1.5.0-beta.1

1.5.0-beta.1

EPSS

Процентиль: 27%
0.00097
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 6 лет назад

There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.

CVSS3: 7.1
redhat
больше 6 лет назад

There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.

CVSS3: 6.1
nvd
около 6 лет назад

There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.

CVSS3: 6.1
debian
около 6 лет назад

There is a vulnerability in all angular versions before 1.5.0-beta.0, ...

EPSS

Процентиль: 27%
0.00097
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79