Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14863

Опубликовано: 15 окт. 2019
Источник: redhat
CVSS3: 7.1

Описание

There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.

A cross-site scripting (XSS) flaw was found in Angular. This flaw occurs due to improper sanitation of xlink:href attributes, which allows the web application to deliver data to users, along with other trusted content, without proper validation.

Дополнительная информация

Статус:

Important
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1763589angular: Cross-site Scripting (XSS) due to no proper sanitization of xlink:href attributes

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 6 лет назад

There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.

CVSS3: 6.1
nvd
около 6 лет назад

There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.

CVSS3: 6.1
debian
около 6 лет назад

There is a vulnerability in all angular versions before 1.5.0-beta.0, ...

CVSS3: 6.1
github
почти 6 лет назад

AngularJS Cross-site Scripting due to failure to sanitize `xlink.href` attributes

7.1 High

CVSS3