Описание
Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '' SVG elements in AngularJS's 'ngSanitize' module allows attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing and also negatively affect the application's performance and behavior by using too large or slow-to-load images. This issue affects AngularJS versions greater than or equal to 1.3.1. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 1.8.3-3 |
| esm-apps/focal | released | 1.7.9-1ubuntu0.1~esm1 |
| esm-apps/jammy | released | 1.8.2-2ubuntu0.1 |
| esm-apps/noble | released | 1.8.3-1ubuntu0.24.04.1 |
| esm-infra/bionic | released | 1.5.10-1ubuntu0.1~esm1 |
| esm-infra/xenial | not-affected | code not present |
| jammy | released | 1.8.2-2ubuntu0.1 |
| noble | released | 1.8.3-1ubuntu0.24.04.1 |
| oracular | ignored | end of life, was ignored [upstream EOL] |
| plucky | released | 1.8.3-1ubuntu0.25.04.1 |
Показывать по
Ссылки на источники
4.8 Medium
CVSS3
Связанные уязвимости
Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '<image>' SVG elements in AngularJS's 'ngSanitize' module allows attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing and also negatively affect the application's performance and behavior by using too large or slow-to-load images. This issue affects AngularJS versions greater than or equal to 1.3.1. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .
Improper sanitization of the value of the 'href' and 'xlink:href' attr ...
AngularJS Incomplete Filtering of Special Elements vulnerability
4.8 Medium
CVSS3