Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-8372

Опубликовано: 09 сент. 2024
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects AngularJS versions 1.3.0-rc.4 and greater. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .

A flaw was found in AngularJS. Improper sanitization of the srcset attribute may allow attackers to bypass common image source restrictions, allowing Content Spoofing.

Меры по смягчению последствий

Currently no mitigation is available for this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Not affected
Red Hat Enterprise Linux 10firefoxNot affected
Red Hat Enterprise Linux 10gjsNot affected
Red Hat Enterprise Linux 10grafanaNot affected
Red Hat Enterprise Linux 10thunderbirdNot affected
Red Hat Enterprise Linux 6firefoxNot affected
Red Hat Enterprise Linux 6thunderbirdNot affected
Red Hat Enterprise Linux 7firefoxNot affected
Red Hat Enterprise Linux 7thunderbirdNot affected
Red Hat Enterprise Linux 8firefoxNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-1289

EPSS

Процентиль: 3%
0.00015
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
ubuntu
больше 1 года назад

Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects AngularJS versions 1.3.0-rc.4 and greater. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .

CVSS3: 4.8
nvd
больше 1 года назад

Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects AngularJS versions 1.3.0-rc.4 and greater. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .

CVSS3: 4.8
debian
больше 1 года назад

Improper sanitization of the value of the 'srcset' attribute in Angula ...

CVSS3: 4.8
github
больше 1 года назад

AngularJS allows attackers to bypass common image source restrictions

CVSS3: 4.8
fstec
больше 1 года назад

Уязвимость JavaScript-фреймворка для разработки одностраничных приложений АngularJS, связанная с неправильной проверкой небезопасной эквивалентности входных данных, позволяющая нарушителю обойти существующие ограничения безопасности и проводить спуфинг-атаки

EPSS

Процентиль: 3%
0.00015
Низкий

4.3 Medium

CVSS3