Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-54152

Опубликовано: 10 дек. 2024
Источник: ubuntu
Приоритет: medium
EPSS Средний

Описание

Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to version 1.4.3, an attacker can write a malicious expression that escapes the sandbox to execute arbitrary code on the system. With a more complex (undisclosed) payload, one can get full access to Arbitrary code execution on the system. The problem has been patched in version 1.4.3 of Angular Expressions. Two possible workarounds are available. One may either disable access to __proto__ globally or make sure that one uses the function with just one argument.

РелизСтатусПримечание
devel

not-affected

cve is for Angular Expressions
esm-apps/focal

not-affected

cve is for Angular Expressions
esm-apps/jammy

not-affected

cve is for Angular Expressions
esm-apps/noble

not-affected

cve is for Angular Expressions
esm-infra/bionic

not-affected

cve is for Angular Expressions
esm-infra/xenial

not-affected

cve is for Angular Expressions
focal

ignored

end of standard support, was needs-triage
jammy

not-affected

cve is for Angular Expressions
noble

not-affected

cve is for Angular Expressions
oracular

ignored

end of life, was needs-triage

Показывать по

EPSS

Процентиль: 95%
0.15817
Средний

Связанные уязвимости

nvd
около 1 года назад

Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to version 1.4.3, an attacker can write a malicious expression that escapes the sandbox to execute arbitrary code on the system. With a more complex (undisclosed) payload, one can get full access to Arbitrary code execution on the system. The problem has been patched in version 1.4.3 of Angular Expressions. Two possible workarounds are available. One may either disable access to `__proto__` globally or make sure that one uses the function with just one argument.

github
около 1 года назад

Angular Expressions - Remote Code Execution when using locals

CVSS3: 9.8
fstec
около 1 года назад

Уязвимость среды проектирования приложений и платформы разработки одностраничных приложений Аngular, связанная с неверным управлением генерацией кода, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 95%
0.15817
Средний