Source: angular.js
X-Debbugs-CC: [email protected]
Severity: important
Tags: security

Hi,

The following vulnerability was published for angular.js.

CVE-2024-8372[0]:
| Improper sanitization of the value of the '[srcset]' attribute in
| AngularJS allows attackers to bypass common image source
| restrictions, which can also lead to a form of  Content Spoofing
| https://owasp.org/www-community/attacks/Content_Spoofing .  This
| issue affects AngularJS versions 1.3.0-rc.4 and greater.  Note: The
| AngularJS project is End-of-Life and will not receive any updates to
| address this issue. For more information see  here
| https://docs.angularjs.org/misc/version-support-status .

https://codepen.io/herodevs/full/xxoQRNL/0072e627abe03e9cda373bc75b4c1017


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2024-8372
    https://www.cve.org/CVERecord?id=CVE-2024-8372

Please adjust the affected versions in the BTS as needed.

Reply via email to