Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-0716

Опубликовано: 29 апр. 2025
Источник: redhat
CVSS3: 4.8
EPSS Низкий

Описание

Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '' SVG elements in AngularJS allows attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing  and also negatively affect the application's performance and behavior by using too large or slow-to-load images. This issue affects all versions of AngularJS. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .

A flaw was found in the angular package. Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '' SVG elements in AngularJS can allow attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing and negatively affect the application's performance and behavior by using too large or slow-to-load images.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Fix deferred
Red Hat Enterprise Linux 10firefoxFix deferred
Red Hat Enterprise Linux 10gjsFix deferred
Red Hat Enterprise Linux 10grafanaFix deferred
Red Hat Enterprise Linux 10thunderbirdFix deferred
Red Hat Enterprise Linux 6firefoxFix deferred
Red Hat Enterprise Linux 6thunderbirdFix deferred
Red Hat Enterprise Linux 7firefoxFix deferred
Red Hat Enterprise Linux 7thunderbirdFix deferred
Red Hat Enterprise Linux 8firefoxFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-791
https://bugzilla.redhat.com/show_bug.cgi?id=2362958angular: AngularJS improper sanitization in SVG '<image>' element

EPSS

Процентиль: 33%
0.00399
Низкий

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
ubuntu
больше 1 года назад

Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '<image>' SVG elements in AngularJS allows attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing and also negatively affect the application's performance and behavior by using too large or slow-to-load images. This issue affects all versions of AngularJS. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .

CVSS3: 4.8
nvd
больше 1 года назад

Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '<image>' SVG elements in AngularJS allows attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing  and also negatively affect the application's performance and behavior by using too large or slow-to-load images. This issue affects all versions of AngularJS. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .

CVSS3: 4.8
debian
больше 1 года назад

Improper sanitization of the value of the 'href' and 'xlink:href' attr ...

CVSS3: 4.8
github
больше 1 года назад

AngularJS improperly sanitizes SVG elements

CVSS3: 4.8
fstec
больше 1 года назад

Уязвимость JavaScript-фреймворка для разработки одностраничных приложений АngularJS, связанная с неполной фильтрацией специальных элементов, позволяющая нарушителю проводить межсайтовые сценарные атаки

EPSS

Процентиль: 33%
0.00399
Низкий

4.8 Medium

CVSS3