Source: angular.js
X-Debbugs-CC: [email protected]
Severity: important
Tags: security

Hi,

The following vulnerability was published for angular.js.

CVE-2024-8373[0]:
| Improper sanitization of the value of the [srcset] attribute in
| <source> HTML elements in AngularJS allows attackers to bypass
| common image source restrictions, which can also lead to a form of
| Content Spoofing https://owasp.org/www-
| community/attacks/Content_Spoofing .  This issue affects all
| versions of AngularJS.  Note: The AngularJS project is End-of-Life
| and will not receive any updates to address this issue. For more
| information see  here https://docs.angularjs.org/misc/version-
| support-status .

https://codepen.io/herodevs/full/bGPQgMp/8da9ce87e99403ee13a295c305ebfa0b


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2024-8373
    https://www.cve.org/CVERecord?id=CVE-2024-8373

Please adjust the affected versions in the BTS as needed.

Reply via email to